pypi

zebo @0.1.0

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2024-11751

Ecosystem

pypi

Summary

Package automatically installs a script with keylogger and screenshots extraction, and sets it for an autostart. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-11-zebo Reasons (based on the campaign): - infostealer - peristence-autorun - keylogger

Source: kam193 (27f62f0f9a2a11b03c5bbead202d9f5d58ca471041e3115eb67dd88accc22be4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.