logo

OceanLotus Hijacks PyPI to Deploy “ZiChatBot” via Enterprise Chat APIs

ID: 819b03ff-8b94-5fe3-a724-d96866b8fc7c

STIX ID: report--819b03ff-8b94-5fe3-a724-d96866b8fc7c

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Ddos

...
...

Kaspersky Labs uncovered a July 2025 supply-chain campaign on PyPI attributed to OceanLotus in which attackers published malicious wheel packages and deceptive wrapper dependencies that load DLL/.SO droppers to install a previously undocumented malware family called ZiChatBot. ZiChatBot targets multiple OSes and uses Zulip public REST APIs as covert C2 to blend with legitimate enterprise web traffic; Kaspersky found ~64% similarity between the dropper and prior OceanLotus tools, and the report warns developers to verify dependency lineage to mitigate this sophisticated, multi-platform supply-chain threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.