Malicious code in ziphash (PyPI)
The ziphash package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and remote code execution capabilities, classified as part of the 2025-11-uzip campaign.
- Disclosed
- Last updated
- Blast radius
- All users who installed the malicious ziphash package from PyPI
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- ziphashPyPI package containing malicious code
The ziphash package published on PyPI was found to contain malicious code injected into the archive-support class initialization routine. Upon package import, the code downloads and executes a remote executable, representing a direct supply chain compromise.\n\nThe malware demonstrates typical infostealer characteristics including obfuscation techniques and multi-stage payload delivery. The incident was identified and attributed to the 2025-11-uzip malware campaign by the OpenSSF's malicious-packages repository.\n\nThe malicious behavior was triggered during normal package initialization, meaning any installation and import of the affected ziphash package would execute the malware without additional user action. This represents a critical supply chain risk to all downstream consumers.
Indicators of compromise
- Packages
- ziphash
Remediation
- Immediately uninstall the ziphash package from all systems
- Scan systems that installed ziphash for signs of malware infection and data exfiltration
- Review package dependencies to identify any projects that depend on ziphash
- Use only verified, trusted versions of archive-handling libraries from reputable sources
- Implement package verification and scanning in your dependency management pipeline
- Monitor for indicators of compromise from the 2025-11-uzip campaign
Sources
- GitHub Advisory GHSA-4277-hrwh-9pfm · GitHub Advisory Database
Cite this entry
"Malicious code in ziphash (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-ziphash-pypi-wasc88
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in idnna (PyPI)
A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package - containedcritical
Malicious code in pydanticc (PyPI)
The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in flasq (PyPI)
A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package