Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·github

Malicious code in zakuchienne (PyPI)

zakuchienne

Risk score

92

AI summary

Indexed incident for zakuchienne (pypi).

Description

Importing the module starts an infostealer


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-11-mescouilles

Reasons (based on the campaign):

  • infostealer

  • infostealer:kiwi

  • infostealer:cstealer

  • exfiltration-generic

  • exfiltration-browser-data

  • exfiltration-credentials

  • files-exfiltration

  • The package contains code to detect if it is running in a sandbox environment.


Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents