Supply-chain threat intelligence

Incident detail

criticalpypi·malware·github

Malicious code in zebo (PyPI)

zebo

Risk score

92

AI summary

Indexed incident for zebo (pypi).

Description

Package automatically installs a script with keylogger and screenshots extraction, and sets it for an autostart.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2024-11-zebo

Reasons (based on the campaign):

  • infostealer

  • peristence-autorun

  • keylogger


Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents