VYPR

pypi · Malicious package advisory

Malware

zsender

MAL-2025-191945

Malicious code in zsender (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (64454f4348553cc0321094cffaef685d8977dd95ccf1c07dc54e2b8b3c39a8f0)
Campaign is split into multiple packages that altogether exfiltrates data from desktop Telegram application.

1. "pyapiepo" is a cover package that provides some useless features BUT also imports "zscaner"
2. "zscaner", when imported, automatically runs a function that is an entry point to the whole process; it uses the "scan" from "reqinstall" to walk through directories. The package also provides main logic: filtering files, triggering archiving directories and exfiltrating them. 
3. "reqinstall" ensures "requests" are installed and provides a directory tree scanning function.
4. "zmaker" provides functions to build archives from collected files.
5. "zsender" provides functions to exfiltrate data, the remote URL and a function to deobfuscate configuration in other packages.

Altogether, they look for "Telegram Desktop" folder, archive user data stored there and exfiltrate to a remote location.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-04-zscaner


Reasons (based on the campaign):


 - target:telegram


 - exfiltration-generic


 - The malicious code is intentionally included in a dependency of the package

Compromised versions (1)

  • 1.2.7

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.