PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux
ID: 745697e6-4e95-50c1-92de-63adbfced00c
STIX ID: report--745697e6-4e95-50c1-92de-63adbfced00c
Feed Name: The Hacker News
Threat Score
**ZiChatBot PyPI supply-chain campaign:** Researchers found three malicious PyPI packages that covertly deliver a new cross‑platform malware family, ZiChatBot, using DLL/.so droppers that establish persistence and execute shellcode retrieved via Zulip REST APIs as a C2 mechanism; packages have been removed and Kaspersky notes code similarity to the OceanLotus (APT32) group, though attribution is uncertain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
