Briefing

PyPI Packages Discovered Delivering New ZiChatBot Malware

security
by [email protected] (The Hacker News) ·

Patch your Python environments by uninstalling the three malicious packages and monitor for ZiChatBot activity.

What to do now

Patch your Python environments by removing the malicious packages, update dependency lists, and monitor for suspicious network activity.

Summary

Three wheel packages on the Python Package Index (PyPI) have been identified by cybersecurity researchers as covert delivery mechanisms for a previously unknown malware family named ZiChatBot. The packages appear legitimate on their PyPI pages but contain hidden code that silently installs ZiChatBot on Windows and Linux systems.

Kaspersky analysts confirmed that the malware is designed to remain undetected while exfiltrating data and establishing persistence. The delivery method relies on the normal pip install process, making it difficult for users to spot the malicious payload. The malware family has not been seen before, indicating a new threat vector for Python developers. The packages were found to execute shell commands that download additional components after installation. The discovery highlights the importance of vetting third‑party dependencies and monitoring post‑install behavior.

Key changes

  • Three PyPI wheel packages identified as malicious
  • Packages covertly install ZiChatBot malware on Windows and Linux
  • Malware remains hidden while exfiltrating data and establishing persistence
  • Delivery occurs through normal pip install, bypassing typical checks
  • Kaspersky confirmed the new ZiChatBot family
  • Packages execute shell commands to download additional components post‑install

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting