logo

Termncolor and Colorinal Explained

ID: 09d197c8-c157-53f5-a840-0008b6ca0004

STIX ID: report--09d197c8-c157-53f5-a840-0008b6ca0004

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-08-15

Date Updated: 2026-05-01

...
...

This analysis describes a malicious Python package chain where 'termncolor' pulls in a dependency 'colorinal' that contains unicode.py, which loads an embedded native library (terminate.dll / terminate.so) to decrypt and drop payloads into %LOCALAPPDATA%\vcpacket (including a signed vcpktsvr.exe and malicious libcef.dll), establish persistence via the HKCU Run key 'pkt-update', and communicate with a Zulip-based C2 to receive and execute shellcode; the report also documents a custom API-hashing routine, a Linux variant, and several file/registry indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.