Thehackernews
OceanLotus Campaign Distributes ZiChatBot Malware via PyPI Packages
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Beginning in July 2025, malicious wheel packages were uploaded to the Python Package Index (PyPI) by the OceanLotus group, delivering a new malware family named ZiChatBot. This malware targets both Windows and Linux systems, utilizing REST APIs from the Zulip chat app for command and control instead of traditional servers. The attack method involved creating benign-looking packages that included malicious dependencies, effectively concealing the malware. Kaspersky's Threat Attribution Engine linked these packages to OceanLotus, confirming the campaign as a supply chain attack. The malicious packages were removed from PyPI after detection, but the incident highlights the ongoing risks associated with software supply chains. Security professionals are urged to remain vigilant against similar threats.
Key Points: • OceanLotus used PyPI to distribute ZiChatBot malware through malicious wheel packages. • The malware operates on both Windows and Linux, utilizing Zulip APIs for C2. • Packages were designed to appear benign, concealing their malicious intent.