HomeSecurityZiChatBot Malware: Malicious PyPI Packages Target Windows and Linux

ZiChatBot Malware: Malicious PyPI Packages Target Windows and Linux

Cybersecurity researchers have discovered three malicious packages on the Python Package Index (PyPI) designed to secretly deliver the new ZiChatBot malware to Windows and Linux. According to Kaspersky, the packages performed their stated functions but had the hidden purpose of delivering malicious files through a carefully designed supply chain attack. This tactic represents a significant evolution in the infiltration methods of APT groups, as it exploits the trust developers have in the Python.

See also: New malware turns Linux systems into P2P attack networks

ZiChatBot
ZiChatBot Malware: Malicious PyPI Packages Target Windows and Linux

The three malicious packages identified are uuid32-utils , colorinal , and termncolor , which were uploaded to PyPI between July 16 and 22, 2025, in a narrow time window that suggests a coordinated attack. The ZiChatBot malware differs from traditional malware in that it does not communicate with a dedicated command-and-control server, but instead uses the REST APIs of the public group chat application Zulip as a control infrastructure. This innovative approach makes detection extremely difficult, as the network traffic appears perfectly legitimate to security monitoring systems

On Windows, when either of the first two packages is installed, the malicious code extracts a DLL dropper named “terminate.dll” and stores it on disk. When the library is imported into a project, the DLL is loaded and acts as a dropper for ZiChatBot. It then creates an auto-run entry in the Windows Registry to ensure persistence on the system and executes code to delete itself from the system, leaving little trace of the original infection. This anti-forensics technique makes incident analysis extremely difficult for security researchers.

Technical Details of ZiChatBot Malware

The Linux version of the shared object dropper ( “terminate.so” ) installs the malware in the path “/tmp/obsHub/obs-check-update” and configures a crontab entry for persistence on the system. Regardless of the operating system, ZiChatBot is designed to execute shellcode that it receives from the C2 server via the Zulip APIs . After executing each command, the malware sends a heart emoji in response to signal to the server that the operation was successful. This confirmation mechanism allows attackers to monitor the status of infected systems in real time.

Kaspersky found that the dropper shares a 64% similarity to another dropper used by the hacking group OceanLotus (also known as APT32 ), which is linked to Vietnam and is considered a state-sponsored threat group. This threat group was observed in late 2024 targeting the Chinese cybersecurity community with infected Visual Studio Code projects disguised as Cobalt Strike plugins , indicating a gradual expansion of their tactics towards the developer ecosystem.

See also: Malicious Laravel Packages on Packagist Install RAT

ZiChatBot Malware: Malicious PyPI Packages Target Windows and Linux
ZiChatBot Malware: Malicious PyPI Packages Target Windows and Linux

Protection and Detection Strategies

To effectively protect against ZiChatBot and similar threats, organizations should adopt a multi-layered security approach. First, monitoring for suspicious HTTP requests to Zulip APIs from systems that should not be communicating with such services can reveal infections. Second, monitoring for modifications to the Windows Registry for new auto-run entries and changes to crontab files on Linux can detect malware installation. Third, using Software Composition Analysis (SCA) that check dependencies for known threats and suspicious behaviors is critical for prevention.

Impact and Protection from Supply Chain Attacks

The PyPI attack highlights the growing threat of supply chain attacks in the software development ecosystem, especially at a time when developers are increasingly relying on third-party libraries. Python packages are a critical asset for millions of developers worldwide, and the contamination of popular libraries can have far-reaching consequences affecting thousands of downstream projects. Organizations should adopt strict dependency control practices, create private PyPI mirrors with vetting processes, and implement approval policies for new packages.

To protect against such threats, developers should verify the authenticity of packages before installation, check the reputation of maintainers through GitHub activity and community feedback, and use dependency pinning with hash verification to ensure the integrity of installations. Additionally, adopting the principle of least privilege in development environments and regularly rotating credentials can limit the impact of a potential infection.

See also: 'Mini Shai-Hulud': SAP-Related npm Packages Compromised with Credential Stealer

ZiChatBot Malware: Malicious PyPI Packages Target Windows and Linux
ZiChatBot Malware: Malicious PyPI Packages Target Windows and Linux

Kaspersky ’s discovery of this campaign demonstrates the continued evolution of APT groups ’ tactics and the need for enhanced security measures in the software supply chain. The use of legitimate services like Zulip for C2 communication represents a new generation of threats that requires advanced detection techniques and behavioral analysis. According to the source , the malicious packages have now been removed from PyPI and the associated Zulip organization has been deactivated, but this case is a reminder of the criticality of proactive security and constant vigilance in software development.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS