logo

OceanLotus suspected of using PyPI to deliver ZiChatBot malware

ID: 0804707b-c50e-5bda-ad2b-d3c6a9bb859c

STIX ID: report--0804707b-c50e-5bda-ad2b-d3c6a9bb859c

Feed Name: Securelist by Kaspersky

Threat Score
80/100

Date Published: 2026-05-06

Date Updated: 2026-05-07

Author: GReAT

...
...

**Executive summary:** A July 2025 PyPI supply‑chain campaign uploaded malicious wheel packages (uuid32-utils, colorinal, termncolor) that extract a dropper (terminate.dll / terminate.so) to install a cross‑platform backdoor named ZiChatBot; the dropper establishes persistence, deploys the payload (vcpktsvr.exe/libcef.dll on Windows or an ELF on Linux), and ZiChatBot uses Zulip public REST APIs as C2; packages were removed from PyPI and the Zulip "helper" organization deactivated, and Kaspersky notes a 64% similarity of the dropper to samples linked to OceanLotus.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.