Malicious code in zhopaorlaaato (PyPI)
The PyPI package zhopaorlaaato contains malicious code that runs an infostealer targeting Telegram and Discord credentials. Depending on version, the infostealer is either embedded in the package or downloaded from a remote URL for execution.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on installation prevalence of zhopaorlaaato package
- Ecosystems
- Attack vectors
- Affected entities
- zhopaorlaaatoPyPI package containing infostealer malware
The PyPI package zhopaorlaaato has been identified as containing malicious code with clear intent to steal credentials. The package runs an infostealer that specifically targets Telegram and Discord credentials, as well as browser data exfiltration.\n\nThe malware implementation varies by package version: some versions have the infostealer embedded directly within the package, while others download and execute a remote malicious script. This dual approach suggests active development and iteration of the attack.\n\nThe campaign has been tracked as 2025-08-dsidelib and was identified through analysis by the OpenSSF's malicious-packages project. The package should be considered actively malicious and poses a direct threat to any system that installs it.
Indicators of compromise
- Packages
- zhopaorlaaato
Remediation
- Immediately uninstall zhopaorlaaato from all systems
- Audit pip package installations for zhopaorlaaato presence
- If installed, assume credential compromise for Telegram and Discord accounts; change passwords and enable 2FA
- Review browser data and authentication tokens for unauthorized access
- Monitor affected systems for signs of data exfiltration or further compromise
- Report the package to PyPI for removal if not already delisted
Sources
- GitHub Advisory GHSA-cqq2-gj5v-42j9 · GitHub Advisory Database
Cite this entry
"Malicious code in zhopaorlaaato (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zhopaorlaaato-pypi-5xh2kf
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedhigh
Malicious code in riakcs (PyPI)
The riakcs package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.
PyPICompromised package - containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in idnna (PyPI)
A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package - containedcritical
Malicious code in pydanticc (PyPI)
The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package