-= Per source details. Do not edit below this line.=-
On import, telebot-bot-run 0.3 executes two attacker-controlled code paths against the installer's host. First, the top-level module fetches https://pastebin.com/raw/xAT1vudj via requests.get and passes the response body directly to exec(), running whatever Python the anonymous, mutable Pastebin URL currently serves under the installer's process. Second, the module hardcodes a Telegram bot token (8951969280:...) and auto-starts an infinitypolling thread that registers handlers /ssh, /get, /collect, /del, /make, and an upload handler. The /ssh handler runs attacker-supplied strings through subprocess.run with shell=True; /get sends any file path on the host to the Telegram chat via bot.senddocument; /collect zips any directory with shutil.make_archive and uploads the archive; /start re-fetches the same Pastebin URL and pipes it into python3 as a detached background process for persistence. The package's setup.py metadata (author='fuckkkkk you 2 3 4', description='Simple Scopper Library') is consistent with the observed behavior rather than a legitimate telebot helper.
The package, distinguished as a speed testing or typosquatted Telegram library, contains a Telegram bot to perform remote control of the computer
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-10-speedd-testing-bot
Reasons (based on the campaign):
typosquatting
Downloads and executes a remote malicious script.
rat
The OpenSSF Package Analysis project identified 'telebot-bot-run' @ 0.5 (pypi) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"iocs": {
"domains": [
"server-unlock-hack.onrender.com",
"i7trak-id3i.onrender.com"
],
"urls": [
"https://pastebin.com/raw/xAT1vudj",
"https://i7trak-id3i.onrender.com",
"https://pastebin.com/raw/M3Rh68JJ",
"https://pastebin.com/raw/77tXxA1d",
"https://pastebin.com/raw/PSPYUQTt",
"https://i7trak-id3i.onrender.com/lol",
"https://pastebin.com/raw/FTLjhBMX"
]
},
"malicious-packages-origins": [
{
"modified_time": "2026-07-20T02:36:22Z",
"source": "ossf-package-analysis",
"versions": [
"0.5"
],
"sha256": "956d172026e3ec8ca278acca488473700f3d28483adf026901c3fcc06f501972",
"import_time": "2026-07-20T04:45:34.040780974Z"
},
{
"modified_time": "2026-07-20T04:42:55.068829Z",
"id": "pypi/2025-10-speedd-testing-bot/telebot-bot-run",
"versions": [
"0.3",
"0.4",
"0.5"
],
"source": "kam193",
"sha256": "3427c3bade820197fefbdc26a5be82d8feeca5f96d35cf035aab848167f2df26",
"import_time": "2026-07-20T06:05:22.564716351Z"
},
{
"modified_time": "2026-07-22T20:26:51Z",
"id": "IN-MAL-2026-010802",
"versions": [
"0.3"
],
"source": "amazon-inspector",
"sha256": "95c556b9ded1648a2523210bf518dea35324c749733eabeef3268795351b1b9c",
"import_time": "2026-07-22T20:31:07.923003827Z"
},
{
"source": "amazon-inspector",
"id": "IN-MAL-2026-010852",
"versions": [
"0.5"
],
"modified_time": "2026-07-22T20:39:49Z",
"sha256": "471d5e59aa7805d8ab169edeee746470f077d1daaebcf14f45376513fe53ae22",
"import_time": "2026-07-22T20:59:16.728580721Z"
},
{
"modified_time": "2026-07-22T20:39:32Z",
"id": "IN-MAL-2026-010850",
"versions": [
"0.4"
],
"source": "amazon-inspector",
"sha256": "dc53581e311e31116c859ea7df64f589623b6b854f292990e0d8bb3fd460c058",
"import_time": "2026-07-22T20:59:16.452521458Z"
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telebot-bot-run/MAL-2026-10863.json"
[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"evidence_files": [
{
"tlsh": "5bf13e81dc5a8caa11fbd69fbb857c60c62687834531f173719c6a206f38354e2a87bc",
"sha256": "d5b201429960ebc96b338e37f77a3b76c6a4e0e152c6558e2974ffd688cf0a06",
"path": "telebot_bot_run/__init__.py"
},
{
"tlsh": "d7e07d934d867e2180f088c805661441f1164b3f253448cb30fd532c5f731824a52524",
"sha256": "581bdf25cec62824322edafbf5ef3975348442c3325046deab3682d44d16caa1",
"path": "setup.py"
}
],
"package_integrity": [
{
"hashes": {
"md5": "b98f05f46a561a375414167e7dfb7903",
"blake2b_256": "27bad7093cf0a8548f66c5a1cdb5d7c4da05d45dfccaa947c8b923ad52c48744",
"sha256": "2f4f084d55e4614038198441b5a5612e9e6ce0b6f89e19a949a16d27f52b15ce"
},
"filename": "telebot_bot_run-0.3-py3-none-any.whl"
},
{
"hashes": {
"md5": "65420a78d42e9c1d0cc6dd52406b1f28",
"blake2b_256": "66b65dfa4de8c57ad52d763e657c688fb48a6923a588fd022f4e78ff5a4d6f47",
"sha256": "659bf15049d26468732d5a9a280fe8ee33394f320a59ed98cf5df008e38e1e39"
},
"filename": "telebot_bot_run-0.3.tar.gz"
}
]
}