home.social

#zichatbotmalware — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #zichatbotmalware, aggregated by home.social.

  1. PyPI Packages Deliver ZiChatBot Malware via Zulip APIs

    Malicious Python packages on PyPI were found to be secretly delivering a new malware called ZiChatBot, which uses Zulip APIs to receive instructions. These seemingly harmless packages covertly dropped malicious components, highlighting the importance of vigilance when downloading code from public repositories.

    osintsights.com/pypi-packages-

    #MalwareOperations #ZichatbotMalware #Pypi #ZulipApis #SupplyChain

  2. OceanLotus Exploits PyPI to Deliver ZiChatBot Malware

    Kaspersky's analysis uncovered a sneaky malware attack on PyPI, where OceanLotus hackers uploaded fake packages that looked like harmless libraries, tricking users into installing the ZiChatBot malware. The malicious packages, uploaded in July 2025, masqueraded as legitimate tools like uuid32-utils, colorinal, and termncolor.

    osintsights.com/oceanlotus-exp

    #Oceanlotus #Pypi #ZichatbotMalware #MalwareOperations #EmergingThreats