Minacce e avversari · Supply chain
La rottura qui non è solo un pacchetto difettoso su PyPI. ZiChatBot usa le API REST pubbliche di Zulip come canale di controllo, quindi gli host infetti possono sembrare normale traffico di chat invece di contattare una chiara infrastruttura malware. Ciò rende il filtering basato sulla destinazione e l’allowlisting delle chat app meno affidabili di quanto assumano i playbook standard.
2 fonti · 7 mag
The Hacker News
PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux
ZiChatBot malware spread via 3 PyPI packages in July 2025 uses Zulip APIs as C2, enabling stealthy attacks across systems
originaleKaspersky Securelist
OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPI
Kaspersky researchers uncovered malicious wheel packages in PyPI that targeted both Windows and Linux and contained a dropper delivering malware dubbed ZiChatBot.
originalePart of the PlainSec briefing for 2026-05-07
Every edition of this story: PyPI Malware nasconde C2 all’interno del traffico di Zulip