logo

PyPI Supply Chain Attack Uncovered: Colorama and Colorizr Name Confusion

ID: 3b036382-99cf-57d2-93b3-9e618ed213fc

STIX ID: report--3b036382-99cf-57d2-93b3-9e618ed213fc

Feed Name: Checkmarx Zero

Threat Score
78/100

Date Published: 2025-05-28

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

Checkmarx researcher Ariel Harush uncovered a cross-platform supply-chain campaign using typo-squatted PyPI packages mimicking colorama/colorizr to deliver Windows and Linux payloads that establish persistence, evade detection, provide remote access (C2), and exfiltrate sensitive data; packages have been removed but IoCs (package owners, GitHub repo, webhook, file hashes) and recommended mitigations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.