Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in zamino (PyPI)

The PyPI package zamino was identified as malicious code—a clone of legitimate Aminoapps libraries with added credential exfiltration functionality. The package was part of the 2025-06-sorex campaign and has been cataloged by the OpenSSF malicious packages database.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on installation count of malicious zamino package
Ecosystems
Attack vectors
Threat actor
Affected entities
  • zaminoMalicious clone of legitimate amino.fix library

The PyPI package zamino was discovered to contain malicious code designed to exfiltrate user credentials. The package is a clone of legitimate libraries used to access Aminoapps (such as amino.fix), with added malicious functionality hidden within library usage patterns.\n\nThe malicious package was part of the 2025-06-sorex campaign, which targeted credential theft through obfuscated code injection in popular library clones. The campaign employed typosquatting or similar techniques to distribute the compromised package.\n\nThe incident was identified and credited to the OpenSSF's malicious packages project, which maintains a public database of confirmed malicious packages across package ecosystems. The package has been cataloged under identifier MAL-2025-191942.

Indicators of compromise

Packages
  • zamino

Remediation

  • Immediately uninstall the zamino package from all environments
  • Audit systems where zamino was installed for credential compromise
  • Rotate any credentials that may have been exposed through systems running zamino
  • Use legitimate amino.fix or other verified Aminoapps libraries instead
  • Monitor PyPI and security advisories for similar typosquatting attempts
  • Implement package verification and allowlisting policies in dependency management

Sources

  1. GitHub Advisory GHSA-jv75-25j3-gqr3 · GitHub Advisory Database

Cite this entry

"Malicious code in zamino (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zamino-pypi-fu1ui8

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in fastapii (PyPI)

    The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    2026 08 FlasqPyPITyposquattingCompromised package
  2. containedcritical

    Malicious code in idnna (PyPI)

    A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    PyPITyposquattingCompromised package
  3. containedcritical

    Malicious code in pydanticc (PyPI)

    The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    2026 08 FlasqPyPITyposquattingCompromised package
  4. containedcritical

    Malicious code in flasq (PyPI)

    A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    PyPITyposquattingCompromised package