Skip to content
supplychainattack.orgSupply chain attack incident catalog

2024 12 Langer Updater supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedhigh

    Malicious code in zip-me (PyPI)

    The PyPI package zip-me contained malicious code designed to exfiltrate system information including IP address and username. The malware was activated during package installation via a metaclass override in setup.py and employed VM-detection techniques to avoid analysis.

    2024 12 Langer UpdaterPyPICompromised package