MAL-2025-193008

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telegreph/MAL-2025-193008.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-193008
Published
2025-12-31T15:00:17Z
Modified
2026-07-20T06:32:31.330058993Z
Summary
Malicious code in telegreph (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (cca72e5a6a205d657e13d29aee3f5448061afd17f222f11db168ef8a20744992)

The package, distinguished as a speed testing or typosquatted Telegram library, contains a Telegram bot to perform remote control of the computer


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-10-speedd-testing-bot

Reasons (based on the campaign):

  • rat

  • Downloads and executes a remote malicious script.

  • typosquatting

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-12-31T15:38:00.900196104Z",
            "sha256": "cca72e5a6a205d657e13d29aee3f5448061afd17f222f11db168ef8a20744992",
            "modified_time": "2025-12-31T15:00:17.235552Z",
            "source": "kam193",
            "id": "pypi/2025-10-speedd-testing-bot/telegreph",
            "versions": [
                "0.2",
                "0.3"
            ]
        },
        {
            "import_time": "2026-01-12T23:35:38.668839481Z",
            "source": "kam193",
            "modified_time": "2025-12-31T15:00:17.235552Z",
            "sha256": "7d8ae36486ed48aca6b53bb6dbb139cf5c1567dd377f09d48d6fb173ea521126",
            "id": "pypi/2025-10-speedd-testing-bot/telegreph",
            "versions": [
                "0.2",
                "0.3"
            ]
        },
        {
            "import_time": "2026-01-18T23:07:34.018122195Z",
            "source": "kam193",
            "modified_time": "2025-12-31T15:00:17.235552Z",
            "sha256": "ca45cc6b3f7fe302114930490eabfda251eb55a13e807e784dbf95c82c2c445c",
            "id": "pypi/2025-10-speedd-testing-bot/telegreph",
            "versions": [
                "0.2",
                "0.3"
            ]
        },
        {
            "import_time": "2026-02-26T09:49:02.348458943Z",
            "source": "kam193",
            "modified_time": "2025-12-31T15:00:17.235552Z",
            "sha256": "7c70b41092e7a6fab378c7071947d46e295858b6af5658b3c22dfe4f69c6ff76",
            "id": "pypi/2025-10-speedd-testing-bot/telegreph",
            "versions": [
                "0.2",
                "0.3"
            ]
        },
        {
            "import_time": "2026-07-20T06:05:22.571310039Z",
            "source": "kam193",
            "modified_time": "2025-12-31T15:00:17.235552Z",
            "sha256": "ce67549907c3121bb62a0781eab7f51eab3b8330548f61d0b0d553c40fac7244",
            "id": "pypi/2025-10-speedd-testing-bot/telegreph",
            "versions": [
                "0.2",
                "0.3"
            ]
        }
    ],
    "iocs": {
        "urls": [
            "https://pastebin.com/raw/xAT1vudj",
            "https://i7trak-id3i.onrender.com",
            "https://pastebin.com/raw/M3Rh68JJ"
        ],
        "domains": [
            "server-unlock-hack.onrender.com"
        ]
    }
}
References
Credits

Affected packages

PyPI / telegreph

Package

Affected ranges

Affected versions

0.*
0.2
0.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telegreph/MAL-2025-193008.json"