Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in ziugxfbvo (PyPI)

The PyPI package ziugxfbvo contained malicious code that executed automatically on import, functioning as an infostealer and remote access trojan (RAT) with capabilities including command execution, file exfiltration, screen recording, and GUI automation.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any system that installed and imported the ziugxfbvo package from PyPI
Ecosystems
Attack vectors
Affected entities
  • ziugxfbvoPyPI package containing malicious code

The ziugxfbvo package published on PyPI contained embedded malicious code that executed automatically during package import. Upon execution, the code downloaded and ran additional payloads that implemented both infostealer and remote access trojan (RAT) functionality.\n\nThe malware connected to a hardcoded command-and-control (C2) server and supported multiple attack capabilities including remote command execution, file exfiltration, screen recording, browser data theft, cryptocurrency wallet targeting, and GUI automation via PyAutoGUI. The package also implemented persistence mechanisms.\n\nThe incident was identified and attributed to the "2026-04-process-support" campaign by the OpenSSF's malicious packages project. The package has been removed from PyPI and the incident is considered resolved.

Indicators of compromise

Packages
  • ziugxfbvo

Remediation

  • Immediately uninstall the ziugxfbvo package from all systems
  • Audit systems that imported ziugxfbvo for signs of compromise including unauthorized file access, network connections, and credential theft
  • Review browser history, saved credentials, and cryptocurrency wallet activity for unauthorized access
  • Monitor for persistence mechanisms and remove any suspicious scheduled tasks or startup entries
  • Consider the affected systems compromised and perform full forensic analysis
  • Change all credentials on affected systems from a clean machine
  • Check for lateral movement to other systems on the network

Sources

  1. GitHub Advisory GHSA-m8qj-cx2w-gp3j · GitHub Advisory Database

Cite this entry

"Malicious code in ziugxfbvo (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-ziugxfbvo-pypi-8o0i7l

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in adpip (PyPI)

    The adpip package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad that published nearly 6000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.

    PyPICompromised package
  2. resolvedcritical

    Malicious code in adstr (PyPI)

    The adstr package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.

    PyPICompromised package
  3. resolvedcritical

    Malicious code in adtool (PyPI)

    The adtool package on PyPI contained malicious code that executed spyware and information-stealing malware. This package was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    PyPICompromised package
  4. resolvedcritical

    Malicious code in afrit-name (PyPI)

    Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package