Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in zsender (PyPI)

A coordinated malicious package campaign on PyPI consisting of five interdependent packages (zsender, zscaner, pyapiepo, reqinstall, zmaker) designed to steal Telegram Desktop user data. The packages work together to locate Telegram Desktop folders, archive user data, and exfiltrate it to a remote server.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Users who installed zsender and its dependency chain (pyapiepo, zscaner, reqinstall, zmaker) on systems with Telegram Desktop installed.
Ecosystems
Attack vectors
Affected entities
  • zsenderExfiltration component providing remote URL and configuration deobfuscation
  • zscanerCore malicious logic; automatically executes on import to filter files and trigger archiving/exfiltration
  • pyapiepoCover package importing zscaner
  • reqinstallEnsures requests installation and provides directory scanning
  • zmakerArchive building functionality

A coordinated malicious package campaign was discovered on PyPI targeting Telegram Desktop users. The campaign consists of five interdependent packages that collectively exfiltrate sensitive data from the Telegram Desktop application.\n\nThe attack chain operates as follows: "pyapiepo" serves as a cover package providing useless features while importing "zscaner"; "zscaner" contains the core malicious logic and automatically executes a function upon import that initiates the data theft process; "reqinstall" ensures the requests library is installed and provides directory tree scanning functionality; "zmaker" builds archives from collected files; and "zsender" handles exfiltration to a remote location and provides configuration deobfuscation functions.\n\nThe malicious packages search for the "Telegram Desktop" folder, archive user data stored within it, and exfiltrate the archives to an attacker-controlled remote server. The campaign was identified and attributed to the OpenSSF's malicious-packages project (campaign identifier: 2025-04-zscaner).

Indicators of compromise

Packages
  • zsender
  • zscaner
  • pyapiepo
  • reqinstall
  • zmaker

Remediation

  • Immediately uninstall zsender, zscaner, pyapiepo, reqinstall, and zmaker from all systems
  • Audit systems for evidence of Telegram Desktop data exfiltration; check for suspicious network connections to unknown remote servers
  • Change Telegram Desktop passwords and enable two-factor authentication
  • Review PyPI package dependencies in projects to identify and remove any reliance on these malicious packages
  • Monitor for similar coordinated multi-package campaigns using the campaign identifier 2025-04-zscaner
  • Report any systems that installed these packages to security teams for forensic analysis

Sources

  1. GitHub Advisory GHSA-h4mw-6gp8-38jj · GitHub Advisory Database

Cite this entry

"Malicious code in zsender (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed April 1, 2025; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zsender-pypi-1oq8xm

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in acloud-clients (PyPI)

    A multi-year malicious campaign on PyPI distributes packages that clone legitimate cloud SDK libraries (acloud-clients, AWS clients) and inject code to exfiltrate cloud credentials via hidden dependencies like time-check-server and snapshot-photo.

    PyPICompromised packageMalicious commit
  2. resolvedcritical

    Malicious code in acloud-client (PyPI)

    A multi-year malicious campaign on PyPI distributed packages (acloud-client, time-check-server, snapshot-photo) that clone legitimate cloud SDK packages and exfiltrate cloud credentials to remote servers. The campaign used obfuscation techniques, hiding malicious functionality in dependency chains.

    PyPICompromised packageMalicious commit
  3. resolvedcritical

    Malicious code in aclient-sdk (PyPI)

    aclient-sdk on PyPI contains malicious code designed to exfiltrate cloud credentials. The package is a clone of the legitimate aliyun-python-sdk-core with injected code that imports a credential-stealing dependency and exfiltrates AWS/Alibaba Cloud tokens to a remote server.

    PyPICompromised packageMalicious commit
  4. resolvedcritical

    Malicious code in zmaker (PyPI)

    A coordinated malicious package campaign on PyPI targeted Telegram Desktop users. Five interdependent packages (zmaker, zscaner, pyapiepo, reqinstall, zsender) worked together to locate, archive, and exfiltrate Telegram user data to a remote server.

    PyPICompromised packageMalicious commit