logo

PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux

ID: 745697e6-4e95-50c1-92de-63adbfced00c

STIX ID: report--745697e6-4e95-50c1-92de-63adbfced00c

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: [email protected] (The Hacker News)

...
...

**ZiChatBot PyPI supply-chain campaign:** Researchers found three malicious PyPI packages that covertly deliver a new cross‑platform malware family, ZiChatBot, using DLL/.so droppers that establish persistence and execute shellcode retrieved via Zulip REST APIs as a C2 mechanism; packages have been removed and Kaspersky notes code similarity to the OceanLotus (APT32) group, though attribution is uncertain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.