Malicious code in zero123 (PyPI)
Malicious code was published in the zero123 package on PyPI as part of a pentest campaign. The package exfiltrates basic system information (hostname, path, username) to the package author upon installation or import.
- Disclosed
- Last updated
- Blast radius
- Unknown; limited to users who installed the malicious zero123 package from PyPI
- Ecosystems
- Attack vectors
- Affected entities
- zero123PyPI package containing malicious code
A malicious package named zero123 was published to PyPI as part of a coordinated campaign (2024-11-byted-dast) of pentest-themed packages. The package was designed to exfiltrate basic system information including hostname, path, and username to the package author when installed or imported.
The attack was classified as a low-harm pentest campaign by the OpenSSF malicious-packages project. The package employed typosquatting and dependency-confusion tactics to increase installation likelihood. The malicious functionality was limited to data exfiltration of non-sensitive system metadata.
The incident was identified and documented by the OpenSSF malicious-packages repository (MAL-2024-11752) and subsequently published as a GitHub Advisory (GHSA-hxjg-gq8r-x2x3).
Indicators of compromise
- Packages
- zero123
Remediation
- Remove the zero123 package from any affected systems
- Audit system logs for suspicious activity or data exfiltration following installation of zero123
- Review PyPI package dependencies to identify and remove any other packages from the 2024-11-byted-dast campaign
- Use dependency scanning tools to detect similar malicious packages in supply chains
Sources
- GitHub Advisory GHSA-hxjg-gq8r-x2x3 · GitHub Advisory Database
Cite this entry
"Malicious code in zero123 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zero123-pypi-4p2n45
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedhigh
Malicious code in adandu (PyPI)
The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.
PyPICompromised packageTyposquattingDependency confusion - resolvedcritical
Malicious code in yelp-pkg (PyPI)
yelp-pkg, a malicious package on PyPI, was designed to exfiltrate sensitive data including environment variables during installation. The package overrides the install command in setup.py to execute malicious code and appears to be a typosquatting attack.
PyPICompromised packageTyposquatting - resolvedhigh
Malicious code in adandv (PyPI)
The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.
PyPICompromised packageTyposquattingDependency confusion - resolvedcritical
Malicious code in zamino (PyPI)
The PyPI package zamino was identified as malicious code—a clone of legitimate Aminoapps libraries with added credential exfiltration functionality. The package was part of the 2025-06-sorex campaign and has been cataloged by the OpenSSF malicious packages database.
2025 06 SorexPyPICompromised packageTyposquatting