Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·github

Malicious code in zenomenallib (PyPI)

zenomenallib

Risk score

92

AI summary

Indexed incident for zenomenallib (pypi).

Description

Package is prepared to exfiltrate sensitive files. Different packages use different places for the malicious code: it runs during importing the module, is placed in a native binary, or in the setup.py script


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-08-xenlib

Reasons (based on the campaign):

  • files-exfiltration

Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents