Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·github

Malicious code in yuzo (PyPI)

yuzo

Risk score

92

AI summary

Indexed incident for yuzo (pypi).

Description

Package contains an infostealer and is clearly prepared for using it. Different versions present different variations, newer are based on CStealer. The exfiltration target is a hardcoded discord webhook


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-09-suyo

Reasons (based on the campaign):

  • infostealer

  • infostealer:cstealer

  • exfiltration-browser-data


Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents