Skip to content
supplychainattack.orgSupply chain attack incident catalog

2026 04 Process Support supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedcritical

    Malicious code in ziugxfbvo (PyPI)

    The PyPI package ziugxfbvo contained malicious code that executed automatically on import, functioning as an infostealer and remote access trojan (RAT) with capabilities including command execution, file exfiltration, screen recording, and GUI automation.

    2026 04 Process SupportPyPICompromised package