Skip to content
supplychainattack.orgSupply chain attack incident catalog

2025 11 Mescouilles supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. containedcritical

    Malicious code in zakuchienne (PyPI)

    The PyPI package zakuchienne contains malicious code that functions as an infostealer, exfiltrating credentials, browser data, and files. The malware includes sandbox detection capabilities and was identified as part of the 2025-11-mescouilles campaign.

    2025 11 MescouillesPyPICompromised package