Skip to content
OceanLotus Campaign Distributes ZiChatBot Malware via PyPI Packages

OceanLotus Campaign Distributes ZiChatBot Malware via PyPI Packages

First seen 7 May 2026, 11:13 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 8, 2026 at 11:08 UTC

Beginning in July 2025, malicious wheel packages were uploaded to the Python Package Index (PyPI) by the OceanLotus group, delivering a new malware family named ZiChatBot. This malware targets both Windows and Linux systems, utilizing REST APIs from the Zulip chat app for command and control instead of traditional servers. The attack method involved creating benign-looking packages that included malicious dependencies, effectively concealing the malware. Kaspersky's Threat Attribution Engine linked these packages to OceanLotus, confirming the campaign as a supply chain attack. The malicious packages were removed from PyPI after detection, but the incident highlights the ongoing risks associated with software supply chains. Security professionals are urged to remain vigilant against similar threats.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 125d ago How this analysis works

Timeline

2025-07-01
Malicious packages uploaded to PyPI
OceanLotus began uploading malicious wheel packages to PyPI, targeting Python users.
Securelist
2026-05-06
Malware discovered and reported
Kaspersky confirmed the discovery of ZiChatBot malware linked to OceanLotus through malicious PyPI packages.
Securelist
2026-05-07
Public announcement of the attack
Multiple cybersecurity outlets reported on the OceanLotus campaign and the use of PyPI for malware distribution.
Ground.News
2026-05-07
Malicious packages removed from PyPI
Following detection, the malicious packages were removed from the Python Package Index to prevent further distribution.
Securelist

More articles in this cluster (10)

Following this threat?

Track OceanLotus and ZiChatBot in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed