Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedhigh

Malicious code in zabitog (PyPI)

Malicious code was discovered in the zabitog package on PyPI. The package contained obfuscated code designed to exfiltrate basic system data such as hostname, IP address, and username. The incident was identified as part of campaign 2026-02-zabitmajeed00 and attributed to OpenSSF's malicious packages research.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Limited to systems that installed the malicious zabitog package from PyPI
Ecosystems
Attack vectors
Affected entities
  • zabitogPyPI package containing obfuscated malicious code

The zabitog package published on PyPI contained obfuscated malicious code intended to exfiltrate basic system information including hostname, IP address, and username from infected systems. The malicious payload was hidden through code obfuscation techniques.

The package was categorized as a likely pentest or research tool based on its characteristics and the limited scope of data exfiltration. It was identified as part of campaign 2026-02-zabitmajeed00 and flagged for both obfuscation and dependency-confusion attack vectors.

The incident was discovered and documented by the OpenSSF's malicious packages project (GitHub advisory GHSA-j279-vpmw-63vw), which maintains a public catalog of confirmed malicious packages across package ecosystems.

Indicators of compromise

Packages
  • zabitog
Hashes
  • 23d4c7f55266f10f23ddf4a743bb4222b920c0e7f4472c1572a51831a3d1f247

Remediation

  • Remove the zabitog package from all systems where it was installed
  • Audit systems that may have installed zabitog for signs of data exfiltration or unauthorized access
  • Review network logs for suspicious outbound connections from affected systems
  • Update dependency management tools to block or alert on zabitog package installations
  • Monitor for similar obfuscated packages in dependency chains

Sources

  1. GitHub Advisory GHSA-j279-vpmw-63vw · GitHub Advisory Database

Cite this entry

"Malicious code in zabitog (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zabitog-pypi-161v6q

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedhigh

    Malicious code in adandu (PyPI)

    The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.

    PyPICompromised packageTyposquattingDependency confusion
  2. resolvedhigh

    Malicious code in adandv (PyPI)

    The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.

    PyPICompromised packageTyposquattingDependency confusion
  3. containedhigh

    Malicious code in yhaplo1 (PyPI)

    Malicious package yhaplo1 was published to PyPI as a dependency confusion attack. The package contained code to exfiltrate basic system information but did not perform active exfiltration. The attacker identified themselves as a HackerOne user conducting a bug bounty test.

    PyPIDependency confusionCompromised package
  4. resolvedhigh

    Malicious code in adanbu (PyPI)

    The PyPI package 'adanbu' version 92.6 contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages on PyPI.

    PyPICompromised packageTyposquattingDependency confusion