Malicious code in zamino (PyPI)
The PyPI package zamino was identified as malicious code—a clone of legitimate Aminoapps libraries with added credential exfiltration functionality. The package was part of the 2025-06-sorex campaign and has been cataloged by the OpenSSF malicious packages database.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on installation count of malicious zamino package
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- zaminoMalicious clone of legitimate amino.fix library
The PyPI package zamino was discovered to contain malicious code designed to exfiltrate user credentials. The package is a clone of legitimate libraries used to access Aminoapps (such as amino.fix), with added malicious functionality hidden within library usage patterns.\n\nThe malicious package was part of the 2025-06-sorex campaign, which targeted credential theft through obfuscated code injection in popular library clones. The campaign employed typosquatting or similar techniques to distribute the compromised package.\n\nThe incident was identified and credited to the OpenSSF's malicious packages project, which maintains a public database of confirmed malicious packages across package ecosystems. The package has been cataloged under identifier MAL-2025-191942.
Indicators of compromise
- Packages
- zamino
Remediation
- Immediately uninstall the zamino package from all environments
- Audit systems where zamino was installed for credential compromise
- Rotate any credentials that may have been exposed through systems running zamino
- Use legitimate amino.fix or other verified Aminoapps libraries instead
- Monitor PyPI and security advisories for similar typosquatting attempts
- Implement package verification and allowlisting policies in dependency management
Sources
- GitHub Advisory GHSA-jv75-25j3-gqr3 · GitHub Advisory Database
Cite this entry
"Malicious code in zamino (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zamino-pypi-fu1ui8
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in yelp-pkg (PyPI)
yelp-pkg, a malicious package on PyPI, was designed to exfiltrate sensitive data including environment variables during installation. The package overrides the install command in setup.py to execute malicious code and appears to be a typosquatting attack.
PyPICompromised packageTyposquatting - resolvedhigh
Malicious code in adandu (PyPI)
The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.
PyPICompromised packageTyposquattingDependency confusion - resolvedhigh
Malicious code in adandv (PyPI)
The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.
PyPICompromised packageTyposquattingDependency confusion - resolvedcritical
Malicious code in youreallydontwantthispackage2132 (PyPI)
Malicious code was published in the PyPI package youreallydontwantthispackage2132 version 1.0.3. The package executes malicious code during installation via setup.py override and communicates with domains associated with malicious activity, exfiltrating environment variables and other data.
PyPICompromised packageTyposquatting