news.mlab.sh
Back to the feed
supply-chain

OceanLotus suspected of using PyPI to deliver ZiChatBot malware

High
Image: Securelist
Summary

Securelist researchers identified a PyPI supply chain attack orchestrated by OceanLotus, utilizing seemingly legitimate Python packages (uuid32-utils, colorinal, and termncolor) to deliver the previously unknown malware family, ZiChatBot. The attack employed a deceptive technique of embedding the malicious package as a dependency, leveraging REST APIs from Zulip for command and control, and utilized a dropper (terminate.dll/so) to deploy the final payload. This highlights the vulnerability of relying on third-party packages and the sophistication of supply chain attacks.

Read the full article at Securelist

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.