Malicious code in zabitog (PyPI)
Malicious code was discovered in the zabitog package on PyPI. The package contained obfuscated code designed to exfiltrate basic system data such as hostname, IP address, and username. The incident was identified as part of campaign 2026-02-zabitmajeed00 and attributed to OpenSSF's malicious packages research.
- Disclosed
- Last updated
- Blast radius
- Limited to systems that installed the malicious zabitog package from PyPI
- Ecosystems
- Attack vectors
- Affected entities
- zabitogPyPI package containing obfuscated malicious code
The zabitog package published on PyPI contained obfuscated malicious code intended to exfiltrate basic system information including hostname, IP address, and username from infected systems. The malicious payload was hidden through code obfuscation techniques.
The package was categorized as a likely pentest or research tool based on its characteristics and the limited scope of data exfiltration. It was identified as part of campaign 2026-02-zabitmajeed00 and flagged for both obfuscation and dependency-confusion attack vectors.
The incident was discovered and documented by the OpenSSF's malicious packages project (GitHub advisory GHSA-j279-vpmw-63vw), which maintains a public catalog of confirmed malicious packages across package ecosystems.
Indicators of compromise
- Packages
- zabitog
- Hashes
- 23d4c7f55266f10f23ddf4a743bb4222b920c0e7f4472c1572a51831a3d1f247
Remediation
- Remove the zabitog package from all systems where it was installed
- Audit systems that may have installed zabitog for signs of data exfiltration or unauthorized access
- Review network logs for suspicious outbound connections from affected systems
- Update dependency management tools to block or alert on zabitog package installations
- Monitor for similar obfuscated packages in dependency chains
Sources
- GitHub Advisory GHSA-j279-vpmw-63vw · GitHub Advisory Database
Cite this entry
"Malicious code in zabitog (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zabitog-pypi-161v6q
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedhigh
Malicious code in adandu (PyPI)
The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.
PyPICompromised packageTyposquattingDependency confusion - resolvedhigh
Malicious code in adandv (PyPI)
The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.
PyPICompromised packageTyposquattingDependency confusion - containedhigh
Malicious code in yhaplo1 (PyPI)
Malicious package yhaplo1 was published to PyPI as a dependency confusion attack. The package contained code to exfiltrate basic system information but did not perform active exfiltration. The attacker identified themselves as a HackerOne user conducting a bug bounty test.
PyPIDependency confusionCompromised package - resolvedhigh
Malicious code in adanbu (PyPI)
The PyPI package 'adanbu' version 92.6 contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages on PyPI.
PyPICompromised packageTyposquattingDependency confusion