Skip to content
supplychainattack.orgSupply chain attack incident catalog
activecritical

Malicious code in zhopaorlaaato (PyPI)

The PyPI package zhopaorlaaato contains malicious code that runs an infostealer targeting Telegram and Discord credentials. Depending on version, the infostealer is either embedded in the package or downloaded from a remote URL for execution.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on installation prevalence of zhopaorlaaato package
Ecosystems
Attack vectors
Affected entities
  • zhopaorlaaatoPyPI package containing infostealer malware

The PyPI package zhopaorlaaato has been identified as containing malicious code with clear intent to steal credentials. The package runs an infostealer that specifically targets Telegram and Discord credentials, as well as browser data exfiltration.\n\nThe malware implementation varies by package version: some versions have the infostealer embedded directly within the package, while others download and execute a remote malicious script. This dual approach suggests active development and iteration of the attack.\n\nThe campaign has been tracked as 2025-08-dsidelib and was identified through analysis by the OpenSSF's malicious-packages project. The package should be considered actively malicious and poses a direct threat to any system that installs it.

Indicators of compromise

Packages
  • zhopaorlaaato

Remediation

  • Immediately uninstall zhopaorlaaato from all systems
  • Audit pip package installations for zhopaorlaaato presence
  • If installed, assume credential compromise for Telegram and Discord accounts; change passwords and enable 2FA
  • Review browser data and authentication tokens for unauthorized access
  • Monitor affected systems for signs of data exfiltration or further compromise
  • Report the package to PyPI for removal if not already delisted

Sources

  1. GitHub Advisory GHSA-cqq2-gj5v-42j9 · GitHub Advisory Database

Cite this entry

"Malicious code in zhopaorlaaato (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zhopaorlaaato-pypi-5xh2kf

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in adpip (PyPI)

    The adpip package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad that published nearly 6000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.

    PyPICompromised package
  2. resolvedcritical

    Malicious code in adstr (PyPI)

    The adstr package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.

    PyPICompromised package
  3. resolvedcritical

    Malicious code in adtool (PyPI)

    The adtool package on PyPI contained malicious code that executed spyware and information-stealing malware. This package was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    PyPICompromised package
  4. resolvedcritical

    Malicious code in afrit-name (PyPI)

    Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package