OceanLotus Hijacks PyPI to Deploy “ZiChatBot” via Enterprise Chat APIs
ID: 819b03ff-8b94-5fe3-a724-d96866b8fc7c
STIX ID: report--819b03ff-8b94-5fe3-a724-d96866b8fc7c
Feed Name: securityonline.info
Kaspersky Labs uncovered a July 2025 supply-chain campaign on PyPI attributed to OceanLotus in which attackers published malicious wheel packages and deceptive wrapper dependencies that load DLL/.SO droppers to install a previously undocumented malware family called ZiChatBot. ZiChatBot targets multiple OSes and uses Zulip public REST APIs as covert C2 to blend with legitimate enterprise web traffic; Kaspersky found ~64% similarity between the dropper and prior OceanLotus tools, and the report warns developers to verify dependency lineage to mitigate this sophisticated, multi-platform supply-chain threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
