MAL-2026-10863

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telebot-bot-run/MAL-2026-10863.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10863
Published
2026-07-20T02:36:22Z
Modified
2026-07-23T07:53:04.501554575Z
Summary
Malicious code in telebot-bot-run (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (95c556b9ded1648a2523210bf518dea35324c749733eabeef3268795351b1b9c)

On import, telebot-bot-run 0.3 executes two attacker-controlled code paths against the installer's host. First, the top-level module fetches https://pastebin.com/raw/xAT1vudj via requests.get and passes the response body directly to exec(), running whatever Python the anonymous, mutable Pastebin URL currently serves under the installer's process. Second, the module hardcodes a Telegram bot token (8951969280:...) and auto-starts an infinitypolling thread that registers handlers /ssh, /get, /collect, /del, /make, and an upload handler. The /ssh handler runs attacker-supplied strings through subprocess.run with shell=True; /get sends any file path on the host to the Telegram chat via bot.senddocument; /collect zips any directory with shutil.make_archive and uploads the archive; /start re-fetches the same Pastebin URL and pipes it into python3 as a detached background process for persistence. The package's setup.py metadata (author='fuckkkkk you 2 3 4', description='Simple Scopper Library') is consistent with the observed behavior rather than a legitimate telebot helper.

Source: kam193 (3427c3bade820197fefbdc26a5be82d8feeca5f96d35cf035aab848167f2df26)

The package, distinguished as a speed testing or typosquatted Telegram library, contains a Telegram bot to perform remote control of the computer


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-10-speedd-testing-bot

Reasons (based on the campaign):

  • typosquatting

  • Downloads and executes a remote malicious script.

  • rat

Source: ossf-package-analysis (956d172026e3ec8ca278acca488473700f3d28483adf026901c3fcc06f501972)

The OpenSSF Package Analysis project identified 'telebot-bot-run' @ 0.5 (pypi) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "iocs": {
        "domains": [
            "server-unlock-hack.onrender.com",
            "i7trak-id3i.onrender.com"
        ],
        "urls": [
            "https://pastebin.com/raw/xAT1vudj",
            "https://i7trak-id3i.onrender.com",
            "https://pastebin.com/raw/M3Rh68JJ",
            "https://pastebin.com/raw/77tXxA1d",
            "https://pastebin.com/raw/PSPYUQTt",
            "https://i7trak-id3i.onrender.com/lol",
            "https://pastebin.com/raw/FTLjhBMX"
        ]
    },
    "malicious-packages-origins": [
        {
            "modified_time": "2026-07-20T02:36:22Z",
            "source": "ossf-package-analysis",
            "versions": [
                "0.5"
            ],
            "sha256": "956d172026e3ec8ca278acca488473700f3d28483adf026901c3fcc06f501972",
            "import_time": "2026-07-20T04:45:34.040780974Z"
        },
        {
            "modified_time": "2026-07-20T04:42:55.068829Z",
            "id": "pypi/2025-10-speedd-testing-bot/telebot-bot-run",
            "versions": [
                "0.3",
                "0.4",
                "0.5"
            ],
            "source": "kam193",
            "sha256": "3427c3bade820197fefbdc26a5be82d8feeca5f96d35cf035aab848167f2df26",
            "import_time": "2026-07-20T06:05:22.564716351Z"
        },
        {
            "modified_time": "2026-07-22T20:26:51Z",
            "id": "IN-MAL-2026-010802",
            "versions": [
                "0.3"
            ],
            "source": "amazon-inspector",
            "sha256": "95c556b9ded1648a2523210bf518dea35324c749733eabeef3268795351b1b9c",
            "import_time": "2026-07-22T20:31:07.923003827Z"
        },
        {
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-010852",
            "versions": [
                "0.5"
            ],
            "modified_time": "2026-07-22T20:39:49Z",
            "sha256": "471d5e59aa7805d8ab169edeee746470f077d1daaebcf14f45376513fe53ae22",
            "import_time": "2026-07-22T20:59:16.728580721Z"
        },
        {
            "modified_time": "2026-07-22T20:39:32Z",
            "id": "IN-MAL-2026-010850",
            "versions": [
                "0.4"
            ],
            "source": "amazon-inspector",
            "sha256": "dc53581e311e31116c859ea7df64f589623b6b854f292990e0d8bb3fd460c058",
            "import_time": "2026-07-22T20:59:16.452521458Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / telebot-bot-run

Package

Affected ranges

Affected versions

0.*
0.3
0.4
0.5

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telebot-bot-run/MAL-2026-10863.json"
cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "evidence_files": [
        {
            "tlsh": "5bf13e81dc5a8caa11fbd69fbb857c60c62687834531f173719c6a206f38354e2a87bc",
            "sha256": "d5b201429960ebc96b338e37f77a3b76c6a4e0e152c6558e2974ffd688cf0a06",
            "path": "telebot_bot_run/__init__.py"
        },
        {
            "tlsh": "d7e07d934d867e2180f088c805661441f1164b3f253448cb30fd532c5f731824a52524",
            "sha256": "581bdf25cec62824322edafbf5ef3975348442c3325046deab3682d44d16caa1",
            "path": "setup.py"
        }
    ],
    "package_integrity": [
        {
            "hashes": {
                "md5": "b98f05f46a561a375414167e7dfb7903",
                "blake2b_256": "27bad7093cf0a8548f66c5a1cdb5d7c4da05d45dfccaa947c8b923ad52c48744",
                "sha256": "2f4f084d55e4614038198441b5a5612e9e6ce0b6f89e19a949a16d27f52b15ce"
            },
            "filename": "telebot_bot_run-0.3-py3-none-any.whl"
        },
        {
            "hashes": {
                "md5": "65420a78d42e9c1d0cc6dd52406b1f28",
                "blake2b_256": "66b65dfa4de8c57ad52d763e657c688fb48a6923a588fd022f4e78ff5a4d6f47",
                "sha256": "659bf15049d26468732d5a9a280fe8ee33394f320a59ed98cf5df008e38e1e39"
            },
            "filename": "telebot_bot_run-0.3.tar.gz"
        }
    ]
}