Malicious code in zhopaorlaaato (PyPI)
The PyPI package zhopaorlaaato contains malicious code that runs an infostealer targeting Telegram and Discord credentials. Depending on version, the infostealer is either embedded in the package or downloaded from a remote URL for execution.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on installation prevalence of zhopaorlaaato package
- Ecosystems
- Attack vectors
- Affected entities
- zhopaorlaaatoPyPI package containing infostealer malware
The PyPI package zhopaorlaaato has been identified as containing malicious code with clear intent to steal credentials. The package runs an infostealer that specifically targets Telegram and Discord credentials, as well as browser data exfiltration.\n\nThe malware implementation varies by package version: some versions have the infostealer embedded directly within the package, while others download and execute a remote malicious script. This dual approach suggests active development and iteration of the attack.\n\nThe campaign has been tracked as 2025-08-dsidelib and was identified through analysis by the OpenSSF's malicious-packages project. The package should be considered actively malicious and poses a direct threat to any system that installs it.
Indicators of compromise
- Packages
- zhopaorlaaato
Remediation
- Immediately uninstall zhopaorlaaato from all systems
- Audit pip package installations for zhopaorlaaato presence
- If installed, assume credential compromise for Telegram and Discord accounts; change passwords and enable 2FA
- Review browser data and authentication tokens for unauthorized access
- Monitor affected systems for signs of data exfiltration or further compromise
- Report the package to PyPI for removal if not already delisted
Sources
- GitHub Advisory GHSA-cqq2-gj5v-42j9 · GitHub Advisory Database
Cite this entry
"Malicious code in zhopaorlaaato (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zhopaorlaaato-pypi-5xh2kf
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in adpip (PyPI)
The adpip package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad that published nearly 6000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.
PyPICompromised package - resolvedcritical
Malicious code in adstr (PyPI)
The adstr package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.
PyPICompromised package - resolvedcritical
Malicious code in adtool (PyPI)
The adtool package on PyPI contained malicious code that executed spyware and information-stealing malware. This package was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
PyPICompromised package - resolvedcritical
Malicious code in afrit-name (PyPI)
Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package