-= Per source details. Do not edit below this line.=-
Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-telegramlite
Reasons (based on the campaign):
target:telegram
files-exfiltration
{
"iocs": {
"urls": [
"https://telegram-full-server.onrender.com/api/upload"
],
"domains": [
"telegram-full-server.onrender.com"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-06-telegramlite/telegramlite",
"versions": [
"1.0.0",
"1.0.1"
],
"sha256": "be464abbf0e3f375f4865ac2802a6b6d96e7af1ce30984d84f464470cdef17dd",
"source": "kam193",
"modified_time": "2026-06-10T19:28:13.195865Z",
"import_time": "2026-06-10T20:19:44.136003474Z"
}
]
}