Malicious code in zamino (PyPI)
Malware
Published
Jul 21, 2026
to the GitHub Advisory Database
•
Updated Jul 21, 2026
Description
Published to the GitHub Advisory Database
Jul 21, 2026
Reviewed
Jul 21, 2026
Last updated
Jul 21, 2026
Source: kam193 (c9ada91851d5e9411f5c74d5ea595be092fc2e4d2e8f7f7c995b6fbb6bd90d00)
Clones of libraries to access Aminoapps (e.g. legitimate package amino.fix) with added exfiltration of the given credentials
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-06-sorex
Reasons (based on the campaign):
exfiltration-credentials
action-hidden-in-lib-usage
clones-real-package
Credit: OpenSSF (source)
References