Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in zking (PyPI)

Malicious code was discovered in the zking package on PyPI. The package contained malicious code that could compromise systems installing it.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users who installed affected versions of zking from PyPI
Ecosystems
Attack vectors
Affected entities
  • zkingPyPI package

The zking package on PyPI was found to contain malicious code. This incident was identified and reported through the OpenSSF's malicious-packages repository.\n\nThe malicious package was published on PyPI under the name zking and posed a direct threat to any user who installed the affected versions. The discovery was credited to the OpenSSF project, which maintains a catalog of known malicious packages in open-source ecosystems.\n\nThe incident has been documented in the GitHub Advisory Database (GHSA-j5fj-m5x6-2892) and tracked in the OpenSSF malicious-packages repository as MAL-2025-41803.

Indicators of compromise

Packages
  • zking

Remediation

  • Remove zking from your Python environment immediately
  • Audit systems where zking was installed for signs of compromise
  • Review package dependencies to ensure no other malicious packages are present
  • Use pip to uninstall: pip uninstall zking
  • Monitor PyPI and security advisories for updates on this incident

Sources

  1. GitHub Advisory GHSA-j5fj-m5x6-2892 · GitHub Advisory Database

Cite this entry

"Malicious code in zking (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed January 1, 2025; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zking-pypi-1xymxr

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in vtranalytic (PyPI)

    The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.

    PyPICompromised packageMalicious maintainer
  2. containedcritical

    Malicious code in govapkg (PyPI)

    govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.

    PyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in dev-helper-bg (PyPI)

    The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.

    2026 07 Make HelperPyPICompromised packageMalicious commit
  4. containedcritical

    Malicious code in karpatkit (PyPI)

    The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.

    PyPICompromised packageMalicious commit