Malicious code in zzzzthisisitwantsafecheckitzzzz (PyPI)
The PyPI package zzzzthisisitwantsafecheckitzzzz version 1.0.0 contained malicious code that downloads and executes remote backdoor trojans during installation when run under specific usernames. The OpenSSF Package Analysis project confirmed the package executes commands associated with malicious behavior.
- Disclosed
- Last updated
- Blast radius
- All users who installed zzzzthisisitwantsafecheckitzzzz version 1.0.0 from PyPI.
- Ecosystems
- Attack vectors
- Affected entities
- zzzzthisisitwantsafecheckitzzzz · 1.0.0
The PyPI package zzzzthisisitwantsafecheckitzzzz version 1.0.0 was identified as malicious by both kam193 and the OpenSSF Package Analysis project. According to the analysis, the package contains code that conditionally downloads and installs two executables identified as backdoor trojans during installation if run under a specific username.\n\nThe OpenSSF Package Analysis project independently confirmed the malicious nature of the package, noting that it executes one or more commands associated with malicious behavior. The campaign identifier 2026-03-thisismytest123 was associated with this malicious distribution.\n\nThe package has been flagged in the GitHub Advisory Database (GHSA-6mg7-v2ff-2qc5) and the OpenSSF malicious packages repository, indicating detection and documentation of the threat.
Indicators of compromise
- Packages
- zzzzthisisitwantsafecheckitzzzz
Remediation
- Immediately uninstall zzzzthisisitwantsafecheckitzzzz from all systems
- Audit systems where the package was installed for signs of compromise, including unauthorized executables and backdoor activity
- Review system logs for suspicious command execution during the package installation period
- If the package was installed under the specific username mentioned in the analysis, conduct a full security investigation of that account and system
- Update dependency management tools to block or alert on this package
- Verify the integrity of any systems that may have executed the malicious payload
Sources
- GitHub Advisory GHSA-6mg7-v2ff-2qc5 · GitHub Advisory Database
Cite this entry
"Malicious code in zzzzthisisitwantsafecheckitzzzz (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-zzzzthisisitwantsafecheckitzzzz-pypi-hb4mir
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in afrit-name (PyPI)
Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m7 (PyPI)
Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adrandom (PyPI)
The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in ziphash (PyPI)
The ziphash package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and remote code execution capabilities, classified as part of the 2025-11-uzip campaign.
2025 11 UzipPyPICompromised package