Malicious code in zlib1g-dev (PyPI)
Malicious code was discovered in the zlib1g-dev package on PyPI. The package was identified by the OpenSSF malicious packages project as containing malicious code.
- Disclosed
- Last updated
- Blast radius
- Unknown scope; PyPI distribution
- Ecosystems
- Attack vectors
- Affected entities
- zlib1g-devPyPI package
The zlib1g-dev package published on PyPI was found to contain malicious code. This incident was identified and documented by the OpenSSF's malicious packages project, which maintains a catalog of known malicious packages across package ecosystems.\n\nThe package appears to be a typosquatting or impersonation attempt, as zlib is a legitimate compression library typically distributed through system package managers (e.g., apt for Debian/Ubuntu) rather than PyPI. The presence of malicious code in this PyPI package represents a supply chain compromise targeting developers who may have mistakenly installed it.\n\nThe incident was disclosed on 2026-07-21 via GitHub Security Advisory GHSA-8vrj-mmvq-hp7r.
Indicators of compromise
- Packages
- zlib1g-dev
Remediation
- Remove zlib1g-dev from PyPI if not already done
- Audit systems and environments where zlib1g-dev was installed
- Review package dependencies and lock files for presence of zlib1g-dev
- Use legitimate zlib packages from official sources (system package managers or verified PyPI packages)
- Monitor for indicators of compromise from systems that may have installed the malicious package
Sources
- GitHub Advisory GHSA-8vrj-mmvq-hp7r · GitHub Advisory Database
Cite this entry
"Malicious code in zlib1g-dev (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zlib1g-dev-pypi-z571s5
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedhigh
Malicious code in cubesat-upstream-driver (PyPI)
Malicious code was published to PyPI in the cubesat-upstream-driver package, capable of collecting environment variables. The package was detected as part of a CTF-like exercise or pentest campaign and does not appear to exfiltrate data autonomously.
PyPICompromised packageDependency confusion - containedcritical
Malicious code in kotanku (PyPI)
The kotanku package on PyPI contained malicious code that exfiltrates cryptocurrency wallet files upon import. The package was identified as part of a coordinated malicious campaign and has been documented by the OpenSSF.
PyPICompromised package - resolvedhigh
Malicious code in riakcs (PyPI)
The riakcs package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.
PyPICompromised package - containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package