{"id":"MAL-2026-10863","summary":"Malicious code in telebot-bot-run (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (95c556b9ded1648a2523210bf518dea35324c749733eabeef3268795351b1b9c)\nOn import, telebot-bot-run 0.3 executes two attacker-controlled code paths against the installer's host. First, the top-level module fetches https://pastebin.com/raw/xAT1vudj via requests.get and passes the response body directly to exec(), running whatever Python the anonymous, mutable Pastebin URL currently serves under the installer's process. Second, the module hardcodes a Telegram bot token (8951969280:...) and auto-starts an infinity_polling thread that registers handlers /ssh, /get, /collect, /del, /make, and an upload handler. The /ssh handler runs attacker-supplied strings through subprocess.run with shell=True; /get sends any file path on the host to the Telegram chat via bot.send_document; /collect zips any directory with shutil.make_archive and uploads the archive; /start re-fetches the same Pastebin URL and pipes it into python3 as a detached background process for persistence. The package's setup.py metadata (author='fuckkkkk you 2 3 4', description='Simple Scopper Library') is consistent with the observed behavior rather than a legitimate telebot helper.\n\n## Source: kam193 (3427c3bade820197fefbdc26a5be82d8feeca5f96d35cf035aab848167f2df26)\nThe package, distinguished as a speed testing or typosquatted Telegram library, contains a Telegram bot to perform remote control of the computer\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-10-speedd-testing-bot\n\n\nReasons (based on the campaign):\n\n\n - typosquatting\n\n\n - Downloads and executes a remote malicious script.\n\n\n - rat\n\n## Source: ossf-package-analysis (956d172026e3ec8ca278acca488473700f3d28483adf026901c3fcc06f501972)\nThe OpenSSF Package Analysis project identified 'telebot-bot-run' @ 0.5 (pypi) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-07-23T07:53:04.501554575Z","published":"2026-07-20T02:36:22Z","database_specific":{"malicious-packages-origins":[{"source":"ossf-package-analysis","sha256":"956d172026e3ec8ca278acca488473700f3d28483adf026901c3fcc06f501972","import_time":"2026-07-20T04:45:34.040780974Z","modified_time":"2026-07-20T02:36:22Z","versions":["0.5"]},{"id":"pypi/2025-10-speedd-testing-bot/telebot-bot-run","modified_time":"2026-07-20T04:42:55.068829Z","versions":["0.3","0.4","0.5"],"source":"kam193","sha256":"3427c3bade820197fefbdc26a5be82d8feeca5f96d35cf035aab848167f2df26","import_time":"2026-07-20T06:05:22.564716351Z"},{"sha256":"95c556b9ded1648a2523210bf518dea35324c749733eabeef3268795351b1b9c","import_time":"2026-07-22T20:31:07.923003827Z","id":"IN-MAL-2026-010802","modified_time":"2026-07-22T20:26:51Z","versions":["0.3"],"source":"amazon-inspector"},{"versions":["0.5"],"source":"amazon-inspector","sha256":"471d5e59aa7805d8ab169edeee746470f077d1daaebcf14f45376513fe53ae22","import_time":"2026-07-22T20:59:16.728580721Z","id":"IN-MAL-2026-010852","modified_time":"2026-07-22T20:39:49Z"},{"id":"IN-MAL-2026-010850","modified_time":"2026-07-22T20:39:32Z","versions":["0.4"],"source":"amazon-inspector","sha256":"dc53581e311e31116c859ea7df64f589623b6b854f292990e0d8bb3fd460c058","import_time":"2026-07-22T20:59:16.452521458Z"}],"iocs":{"urls":["https://pastebin.com/raw/xAT1vudj","https://i7trak-id3i.onrender.com","https://pastebin.com/raw/M3Rh68JJ","https://pastebin.com/raw/77tXxA1d","https://pastebin.com/raw/PSPYUQTt","https://i7trak-id3i.onrender.com/lol","https://pastebin.com/raw/FTLjhBMX"],"domains":["server-unlock-hack.onrender.com","i7trak-id3i.onrender.com"]}},"references":[{"type":"WEB","url":"https://www.getsafety.com/blog-posts/telegrem-bot-malware"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/telebot-bot-run"},{"type":"PACKAGE","url":"https://pypi.org/project/telebot-bot-run/0.3/"},{"type":"PACKAGE","url":"https://pypi.org/project/telebot-bot-run/0.5/"},{"type":"PACKAGE","url":"https://pypi.org/project/telebot-bot-run/0.4/"}],"affected":[{"package":{"name":"telebot-bot-run","ecosystem":"PyPI","purl":"pkg:pypi/telebot-bot-run"},"versions":["0.5","0.3","0.4"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"telebot_bot_run-0.3-py3-none-any.whl","hashes":{"blake2b_256":"27bad7093cf0a8548f66c5a1cdb5d7c4da05d45dfccaa947c8b923ad52c48744","md5":"b98f05f46a561a375414167e7dfb7903","sha256":"2f4f084d55e4614038198441b5a5612e9e6ce0b6f89e19a949a16d27f52b15ce"}},{"filename":"telebot_bot_run-0.3.tar.gz","hashes":{"md5":"65420a78d42e9c1d0cc6dd52406b1f28","sha256":"659bf15049d26468732d5a9a280fe8ee33394f320a59ed98cf5df008e38e1e39","blake2b_256":"66b65dfa4de8c57ad52d763e657c688fb48a6923a588fd022f4e78ff5a4d6f47"}}],"evidence_files":[{"path":"telebot_bot_run/__init__.py","sha256":"d5b201429960ebc96b338e37f77a3b76c6a4e0e152c6558e2974ffd688cf0a06","tlsh":"5bf13e81dc5a8caa11fbd69fbb857c60c62687834531f173719c6a206f38354e2a87bc"},{"path":"setup.py","sha256":"581bdf25cec62824322edafbf5ef3975348442c3325046deab3682d44d16caa1","tlsh":"d7e07d934d867e2180f088c805661441f1164b3f253448cb30fd532c5f731824a52524"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telebot-bot-run/MAL-2026-10863.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}