Skip to content
supplychainattack.orgSupply chain attack incident catalog

2025 11 Uzip supply chain incidents

2 confirmed incidents publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedcritical

    Malicious code in yzip (PyPI)

    The yzip package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and infosteal capabilities, tracked as campaign 2025-11-uzip.

    2025 11 UzipPyPICompromised package
  2. resolvedcritical

    Malicious code in ziphash (PyPI)

    The ziphash package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and remote code execution capabilities, classified as part of the 2025-11-uzip campaign.

    2025 11 UzipPyPICompromised package