{"id":"MAL-2026-6051","summary":"Malicious code in telegram-lite-grabber (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (aad489fe689e441f3237d052bb24702e3178fca26564e662b060c0a8d01fe5f9)\nPackage is named 'telegram-lite-grabber', a name strongly suggestive of a tool intended to harvest Telegram credentials or session data. No concrete malicious behavior was identified in the scanned files, and no install-time or import-time harmful code paths were observed. The name alone, however, warrants human review to assess whether the package distributes attack tooling, contains a payload not surfaced by automated checks, or is otherwise unsuitable for the registry.\n\n## Source: kam193 (70271d13337a92afafb6d5db770a6d73cd960b6910992013d57ec24388ab8fa8)\nPackage exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-telegramlite\n\n\nReasons (based on the campaign):\n\n\n - target:telegram\n\n\n - files-exfiltration\n","modified":"2026-07-09T16:32:05.805938568Z","published":"2026-06-17T07:09:46Z","database_specific":{"iocs":{"urls":["https://telegram-full-server.onrender.com/api/upload"],"domains":["telegram-full-server.onrender.com"]},"malicious-packages-origins":[{"versions":["1.0.0"],"source":"kam193","sha256":"70271d13337a92afafb6d5db770a6d73cd960b6910992013d57ec24388ab8fa8","import_time":"2026-06-17T07:59:47.587995782Z","id":"pypi/2026-06-telegramlite/telegram-lite-grabber","modified_time":"2026-06-17T07:09:46.746917Z"},{"id":"IN-MAL-2026-009181","modified_time":"2026-07-09T15:40:10Z","versions":["1.0.0"],"source":"amazon-inspector","sha256":"aad489fe689e441f3237d052bb24702e3178fca26564e662b060c0a8d01fe5f9","import_time":"2026-07-09T16:20:48.818357212Z"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/telegram-lite-grabber"},{"type":"PACKAGE","url":"https://pypi.org/project/telegram-lite-grabber/1.0.0/"}],"affected":[{"package":{"name":"telegram-lite-grabber","ecosystem":"PyPI","purl":"pkg:pypi/telegram-lite-grabber"},"versions":["1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"telegram_lite_grabber-1.0.0-py3-none-any.whl","hashes":{"sha256":"3cc223f8e8a24d27120a36d1b10929cc14d740bb0ba69e6ff85b03784e48079c","blake2b_256":"5c822bfd6ead61f3299c0dda532b69dd29faa054ca5e535e60204af3c7954af7","md5":"679672e2cbc3260c35aa8e2f8ea9da32"}},{"hashes":{"md5":"ee798f07895ce403f408dbd7048ff70b","sha256":"bbdea4cc473ada717e0dab5ab390b0232bc9dd0abea188358380c075c06050f9","blake2b_256":"7dabb21d1fe2293c77c679a9570d9f6d2952706095ddfb653a78d131e02d0afe"},"filename":"telegram_lite_grabber-1.0.0.tar.gz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telegram-lite-grabber/MAL-2026-6051.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}