Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in zscaner (PyPI)

A coordinated malicious package campaign on PyPI targeting Telegram Desktop users. Five interdependent packages (zscaner, pyapiepo, reqinstall, zmaker, zsender) work together to locate, archive, and exfiltrate Telegram Desktop user data to a remote server.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Users who installed zscaner and its dependency chain (pyapiepo, reqinstall, zmaker, zsender) from PyPI
Ecosystems
Attack vectors
Affected entities
  • zscanerPrimary malicious package; runs exfiltration logic on import
  • pyapiepoCover package that imports zscaner
  • reqinstallProvides directory scanning functionality
  • zmakerProvides archive building functions
  • zsenderProvides data exfiltration and configuration deobfuscation

A multi-package malicious campaign was discovered on PyPI designed to steal data from Telegram Desktop installations. The campaign consists of five coordinated packages that together form an infostealer:

Package roles:

  • pyapiepo: A cover package providing useless features while importing the malicious zscaner package
  • zscaner: The primary malicious package that executes automatically on import, orchestrating the entire exfiltration process
  • reqinstall: Ensures the requests library is installed and provides directory tree scanning functionality
  • zmaker: Provides archive creation functions for collected files
  • zsender: Handles data exfiltration to remote servers and configuration deobfuscation

Attack flow: When any of these packages are imported, the malicious code searches for the "Telegram Desktop" folder, archives user data stored there, and exfiltrates it to an attacker-controlled remote location. The campaign was identified as part of the OpenSSF's malicious packages tracking effort.

Indicators of compromise

Packages
  • zscaner
  • pyapiepo
  • reqinstall
  • zmaker
  • zsender

Remediation

  • Immediately uninstall zscaner, pyapiepo, reqinstall, zmaker, and zsender from all systems
  • Audit PyPI package dependencies in your projects to identify if any of these packages were installed
  • If Telegram Desktop was installed on affected systems, assume Telegram user data may have been compromised; change Telegram credentials and enable two-factor authentication
  • Review network logs for outbound connections to the exfiltration endpoint identified in the malicious package
  • Use package pinning and dependency scanning tools to prevent installation of malicious packages
  • Monitor PyPI for similar multi-package campaigns targeting specific applications

Sources

  1. GitHub Advisory GHSA-7h98-3phx-875g · GitHub Advisory Database

Cite this entry

"Malicious code in zscaner (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zscaner-pypi-13cho4

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in alphalend-layouts (PyPI)

    The PyPI package alphalend-layouts contained malicious code that harvested Sui keystores, private keys, and environment secrets from installer systems and uploaded them to an attacker-controlled GitHub repository. The attack was triggered both during installation and on first import, with credentials deliberately obfuscated to evade detection.

    PyPICompromised packageMalicious commit
  2. containedcritical

    Malicious code in aichannel (PyPI)

    Multiple malicious PyPI packages (aichannel, cognikit, aiassistcore) were published as part of a coordinated campaign attributed to North Korea's "Contagious Interview" operation. The packages contain infostealer functionality including cryptocurrency wallet address replacement, browser data exfiltration, keylogging, clipboard monitoring, and remote access capabilities.

    Contagious InterviewPyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in ailaunchkit (PyPI)

    A coordinated campaign of malicious Python packages on PyPI (ailaunchkit, cognikit, aiassistcore, aichannel) was discovered containing infostealer malware. The packages implement cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, with IoCs consistent with North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  4. containedcritical

    Malicious code in aiassistcore (PyPI)

    Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.

    Contagious InterviewPyPICompromised packageMalicious commit