-= Per source details. Do not edit below this line.=-
Package implements a Telegram-bot-driven remote administration tool that gives whoever holds the configured bot token full control of the installer's host. A polling loop calls the Telegram getUpdates API and dispatches received messages as shell commands through subprocess.run (SystemAnalyzer.execute_analysis), exposing a documented run command to execute arbitrary system commands. Additional handlers (findbot/getallbots) walk the filesystem (/, /home, /root, /etc, /var/www, /opt, /usr/local, /tmp, Windows drive roots and user profile directories), read.py/.json/.conf/.cfg/.env/.ini files, and regex-extract third-party Telegram bot tokens (BOT_TOKEN, API_TOKEN, TELEGRAM_TOKEN, [0-9]+:[A-Za-z0-9_-]+), returning them to the remote operator. File and credential exfiltration handlers (getfile, getdir, findget, getsystem, getconfig, getpasswords, getsshkeys, rdpall) read arbitrary installer paths — including SSH keys and stored credentials — and upload them to the operator's Telegram chat via requests.post to api.telegram.org sendDocument. The package advertises itself as a 'Complete VPS Control System' with 168+ admin commands including user creation and firewall modification.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-010962",
"sha256": "ebce016051a9e9cb604067185042ce49c7426aa1ac01aa606e430c4d1120eec7",
"modified_time": "2026-07-28T13:42:28Z",
"import_time": "2026-07-28T14:20:01.586361715Z",
"versions": [
"9.0.1"
],
"source": "amazon-inspector"
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/vtranalytic/MAL-2026-11156.json"
[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"sha256": "e02e402bd389c7fe56c476c13264633990f580253315577e06163a0876ab20a4",
"tlsh": "67e284a2cc68380742b2d65d4946e4a2f2216343525a8c13fdbc95bc1f30767b6f6abd",
"path": "vtranalytic/vtranalytic.py"
}
],
"package_integrity": [
{
"filename": "vtranalytic-9.0.1-py3-none-any.whl",
"hashes": {
"sha256": "b19a86859bc10931a8ae41e24262623e50e51eff462759145af7cef5f23c1681",
"blake2b_256": "4d6f6c662de9bc7c219ffa5f53dd39ee439571cb7a295f2addd88f08cb048164",
"md5": "a36bb51112b583f89c99c786eedc2a67"
}
},
{
"filename": "vtranalytic-9.0.1.tar.gz",
"hashes": {
"sha256": "edfcab06e3ce6d1ca1323b4e1fdb25188a331700725d3e60966937d088b5f838",
"blake2b_256": "852f9239824f5bfd71fa3912d9695fa167a9f335ca891334ef8145c35ca7392a",
"md5": "8ed64f110e085230f7276fb7ed6d2524"
}
}
]
}