Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedhigh

Malicious code in zero123 (PyPI)

Malicious code was published in the zero123 package on PyPI as part of a pentest campaign. The package exfiltrates basic system information (hostname, path, username) to the package author upon installation or import.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; limited to users who installed the malicious zero123 package from PyPI
Ecosystems
Attack vectors
Affected entities
  • zero123PyPI package containing malicious code

A malicious package named zero123 was published to PyPI as part of a coordinated campaign (2024-11-byted-dast) of pentest-themed packages. The package was designed to exfiltrate basic system information including hostname, path, and username to the package author when installed or imported.

The attack was classified as a low-harm pentest campaign by the OpenSSF malicious-packages project. The package employed typosquatting and dependency-confusion tactics to increase installation likelihood. The malicious functionality was limited to data exfiltration of non-sensitive system metadata.

The incident was identified and documented by the OpenSSF malicious-packages repository (MAL-2024-11752) and subsequently published as a GitHub Advisory (GHSA-hxjg-gq8r-x2x3).

Indicators of compromise

Packages
  • zero123

Remediation

  • Remove the zero123 package from any affected systems
  • Audit system logs for suspicious activity or data exfiltration following installation of zero123
  • Review PyPI package dependencies to identify and remove any other packages from the 2024-11-byted-dast campaign
  • Use dependency scanning tools to detect similar malicious packages in supply chains

Sources

  1. GitHub Advisory GHSA-hxjg-gq8r-x2x3 · GitHub Advisory Database

Cite this entry

"Malicious code in zero123 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zero123-pypi-4p2n45

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedhigh

    Malicious code in adandu (PyPI)

    The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.

    PyPICompromised packageTyposquattingDependency confusion
  2. resolvedcritical

    Malicious code in yelp-pkg (PyPI)

    yelp-pkg, a malicious package on PyPI, was designed to exfiltrate sensitive data including environment variables during installation. The package overrides the install command in setup.py to execute malicious code and appears to be a typosquatting attack.

    PyPICompromised packageTyposquatting
  3. resolvedhigh

    Malicious code in adandv (PyPI)

    The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.

    PyPICompromised packageTyposquattingDependency confusion
  4. resolvedcritical

    Malicious code in zamino (PyPI)

    The PyPI package zamino was identified as malicious code—a clone of legitimate Aminoapps libraries with added credential exfiltration functionality. The package was part of the 2025-06-sorex campaign and has been cataloged by the OpenSSF malicious packages database.

    2025 06 SorexPyPICompromised packageTyposquatting