OceanLotus suspected of using PyPI to deliver ZiChatBot malware
Kaspersky researchers discovered malicious Python wheel packages uploaded to PyPI in July 2025 that delivered a previously unknown malware family called ZiChatBot, attributed to OceanLotus APT. The attack targeted both Windows and Linux users through three fake libraries (uuid32-utils, colorinal, termncolor) that acted as droppers, with ZiChatBot using Zulip's public REST APIs as command-and-control infrastructure instead of traditional servers. The packages were removed from PyPI and the attacker's Zulip organization deactivated before widespread infections occurred.