supply-chain
OceanLotus suspected of using PyPI to deliver ZiChatBot malware
High
Summary
Securelist researchers identified a PyPI supply chain attack orchestrated by OceanLotus, utilizing seemingly legitimate Python packages (uuid32-utils, colorinal, and termncolor) to deliver the previously unknown malware family, ZiChatBot. The attack employed a deceptive technique of embedding the malicious package as a dependency, leveraging REST APIs from Zulip for command and control, and utilized a dropper (terminate.dll/so) to deploy the final payload. This highlights the vulnerability of relying on third-party packages and the sophistication of supply chain attacks.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
