{"id":"MAL-2026-5531","summary":"Malicious code in telegramlite (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ce1afd32bb4808a41c70c2b9e7d38d36de85eef1ada8d8ae615f5df1a6f88a5c)\nNo install-time, import-time, or runtime behaviors of concern were observed in this version. The package name suggests a lightweight Telegram client wrapper, but no code paths matching credential theft, exfiltration, dropper, silent-relay, or backdoor patterns were identified in the scanned files. Routing to human review for name-similarity assessment against established Telegram client libraries before publishing a verdict.\n\n## Source: kam193 (be464abbf0e3f375f4865ac2802a6b6d96e7af1ce30984d84f464470cdef17dd)\nPackage exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-telegramlite\n\n\nReasons (based on the campaign):\n\n\n - target:telegram\n\n\n - files-exfiltration\n","modified":"2026-07-09T16:32:06.011197085Z","published":"2026-06-10T19:28:13Z","database_specific":{"iocs":{"domains":["telegram-full-server.onrender.com"],"urls":["https://telegram-full-server.onrender.com/api/upload"]},"malicious-packages-origins":[{"modified_time":"2026-06-10T19:28:13.195865Z","versions":["1.0.0","1.0.1"],"source":"kam193","sha256":"be464abbf0e3f375f4865ac2802a6b6d96e7af1ce30984d84f464470cdef17dd","import_time":"2026-06-10T20:19:44.136003474Z","id":"pypi/2026-06-telegramlite/telegramlite"},{"id":"IN-MAL-2026-009184","modified_time":"2026-07-09T15:40:35Z","versions":["1.0.1"],"source":"amazon-inspector","sha256":"2f68222af052b28841bed7472ec0a37eb4b826d6baa44cd831538a067a9ac054","import_time":"2026-07-09T16:20:49.097350651Z"},{"modified_time":"2026-07-09T15:40:18Z","versions":["1.0.0"],"source":"amazon-inspector","sha256":"ce1afd32bb4808a41c70c2b9e7d38d36de85eef1ada8d8ae615f5df1a6f88a5c","import_time":"2026-07-09T16:20:48.916763279Z","id":"IN-MAL-2026-009182"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/telegramlite"},{"type":"PACKAGE","url":"https://pypi.org/project/telegramlite/1.0.1/"},{"type":"PACKAGE","url":"https://pypi.org/project/telegramlite/1.0.0/"}],"affected":[{"package":{"name":"telegramlite","ecosystem":"PyPI","purl":"pkg:pypi/telegramlite"},"versions":["1.0.0","1.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telegramlite/MAL-2026-5531.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"telegramlite-1.0.1-py3-none-any.whl","hashes":{"md5":"3228c16ca76b963524b998bbcfd49057","sha256":"ace355a39f35f9b9c7d074a5b014bb1415ae495839a489515729d6f44a05eac6","blake2b_256":"56294bbc815eda15470489ab22f523eb58e9e0730238e0c4140a4712c05b1a6d"}},{"filename":"telegramlite-1.0.1.tar.gz","hashes":{"sha256":"adbed80fd97ee185c90597b96f11bc58d149042140619b28cff6e438c1c2cb26","blake2b_256":"b2698eb89376627cc57e48c7ae3bcc2f03ea4677fbc52d7f350a37cbe774181f","md5":"fe5a12f33c4397950ddb65103ef33352"}}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}