-= Per source details. Do not edit below this line.=-
Campaign is split into multiple packages that altogether exfiltrates data from desktop Telegram application.
Altogether, they look for "Telegram Desktop" folder, archive user data stored there and exfiltrate to a remote location.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-04-zscaner
Reasons (based on the campaign):
target:telegram
exfiltration-generic
The malicious code is intentionally included in a dependency of the package
{
"malicious-packages-origins": [
{
"sha256": "1efe69752fd9b5fc4bb5712690e4f0f9bc53b6ce064a36f47099c69e8c5f8f3d",
"source": "reversing-labs",
"modified_time": "2025-05-22T12:33:45Z",
"id": "RLMA-2025-02595",
"versions": [
"1.0.1",
"1.1.0"
],
"import_time": "2025-05-22T14:06:37.465137224Z"
},
{
"sha256": "14ef3a9cd087aa6eaa13b2eebfef3239602dc8ff30a8ddc4508d6762aa38c342",
"source": "kam193",
"modified_time": "2025-04-20T12:05:56Z",
"id": "pypi/2025-04-zscaner/reqinstall",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.532555924Z"
},
{
"sha256": "fabb4dfb4f519f848a714f96e09e2b5fbb289ffdd8cd86fc13c8fbf49b539962",
"source": "kam193",
"modified_time": "2025-04-20T12:05:56Z",
"id": "pypi/2025-04-zscaner/reqinstall",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.570329289Z"
},
{
"sha256": "783763ebdfa4122fcaa11495aab7006a4771040ef9c11a1d274356be7552a37f",
"source": "kam193",
"modified_time": "2025-04-20T12:05:56Z",
"id": "pypi/2025-04-zscaner/reqinstall",
"versions": [
"1.0.1",
"1.1.0"
],
"import_time": "2025-12-10T21:38:57.779299203Z"
},
{
"sha256": "a3ba2157bc4864351efb57f77ff00f31e03bfc0ccfc3ca93d192b09ac62daec1",
"source": "reversing-labs",
"modified_time": "2026-03-18T12:18:09Z",
"id": "RLUA-2026-00699",
"import_time": "2026-03-19T12:20:21.893993973Z"
}
],
"iocs": {
"ips": [
"77.91.76.45"
],
"urls": [
"http://77.91.76.45:100/OPEN"
]
}
}