Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in zmaker (PyPI)

A coordinated malicious package campaign on PyPI targeted Telegram Desktop users. Five interdependent packages (zmaker, zscaner, pyapiepo, reqinstall, zsender) worked together to locate, archive, and exfiltrate Telegram user data to a remote server.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Users who installed zmaker and its dependency chain (pyapiepo, zscaner, reqinstall, zsender) on systems with Telegram Desktop installed.
Ecosystems
Attack vectors
Affected entities
  • zmakerProvides archive building functions for exfiltration
  • zscanerCore malicious package that triggers data collection and exfiltration
  • pyapiepoCover package that imports zscaner
  • reqinstallProvides directory scanning functionality
  • zsenderHandles data exfiltration to remote server

A coordinated malicious package campaign was discovered on PyPI consisting of five interdependent packages designed to steal data from Telegram Desktop installations. The campaign, identified as 2025-04-zscaner, used a modular architecture where each package served a specific function in the attack chain.\n\nThe attack flow begins with "pyapiepo," a cover package providing useless features while importing the core malicious package "zscaner." When zscaner is imported, it automatically executes functions that initiate the data theft process. The "reqinstall" package ensures the requests library is available and provides directory tree scanning capabilities. The "zmaker" package builds archives from collected files, while "zsender" handles exfiltration to a remote location and provides configuration deobfuscation functions.\n\nTogether, these packages search for the Telegram Desktop folder, archive user data stored there, and exfiltrate it to an attacker-controlled remote server. The malicious code was intentionally included as a dependency chain, making it difficult for users to identify the threat.\n\nThe campaign was identified and credited to the OpenSSF's malicious-packages repository, which tracks confirmed malicious packages across package ecosystems.

Indicators of compromise

Packages
  • zmaker
  • zscaner
  • pyapiepo
  • reqinstall
  • zsender

Remediation

  • Immediately uninstall zmaker, zscaner, pyapiepo, reqinstall, and zsender from all systems
  • Audit pip package installation logs to identify affected systems and users
  • If Telegram Desktop was installed on affected systems, assume Telegram user data (messages, contacts, media) may have been compromised
  • Change Telegram account passwords and enable two-factor authentication
  • Monitor for unauthorized access to Telegram accounts
  • Implement package pinning and dependency verification in development workflows
  • Use tools like pip-audit or safety to scan for known malicious packages
  • Review and restrict PyPI package sources in organizational policies

Sources

  1. GitHub Advisory GHSA-qjr9-wxqm-hw3x · GitHub Advisory Database

Cite this entry

"Malicious code in zmaker (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zmaker-pypi-leom3i

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in acloud-clients (PyPI)

    A multi-year malicious campaign on PyPI distributes packages that clone legitimate cloud SDK libraries (acloud-clients, AWS clients) and inject code to exfiltrate cloud credentials via hidden dependencies like time-check-server and snapshot-photo.

    PyPICompromised packageMalicious commit
  2. resolvedcritical

    Malicious code in acloud-client (PyPI)

    A multi-year malicious campaign on PyPI distributed packages (acloud-client, time-check-server, snapshot-photo) that clone legitimate cloud SDK packages and exfiltrate cloud credentials to remote servers. The campaign used obfuscation techniques, hiding malicious functionality in dependency chains.

    PyPICompromised packageMalicious commit
  3. resolvedcritical

    Malicious code in zscaner (PyPI)

    A coordinated malicious package campaign on PyPI targeting Telegram Desktop users. Five interdependent packages (zscaner, pyapiepo, reqinstall, zmaker, zsender) work together to locate, archive, and exfiltrate Telegram Desktop user data to a remote server.

    PyPICompromised packageMalicious commit
  4. containedcritical

    Malicious code in xyq-drama-skill (PyPI)

    xyq-drama-skill, a PyPI package, contained malicious code that downloads and executes an unsigned binary from a remote server during installation and on command invocation. The package masquerades as a Chinese short-video drama script generator but actually deploys what appears to be a COFFLoader beacon.

    PyPICompromised packageMalicious commit