MAL-2026-5531

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telegramlite/MAL-2026-5531.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5531
Published
2026-06-10T19:28:13Z
Modified
2026-07-09T16:32:06.011197085Z
Summary
Malicious code in telegramlite (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (ce1afd32bb4808a41c70c2b9e7d38d36de85eef1ada8d8ae615f5df1a6f88a5c)

No install-time, import-time, or runtime behaviors of concern were observed in this version. The package name suggests a lightweight Telegram client wrapper, but no code paths matching credential theft, exfiltration, dropper, silent-relay, or backdoor patterns were identified in the scanned files. Routing to human review for name-similarity assessment against established Telegram client libraries before publishing a verdict.

Source: kam193 (be464abbf0e3f375f4865ac2802a6b6d96e7af1ce30984d84f464470cdef17dd)

Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-telegramlite

Reasons (based on the campaign):

  • target:telegram

  • files-exfiltration

Database specific
{
    "iocs": {
        "urls": [
            "https://telegram-full-server.onrender.com/api/upload"
        ],
        "domains": [
            "telegram-full-server.onrender.com"
        ]
    },
    "malicious-packages-origins": [
        {
            "versions": [
                "1.0.0",
                "1.0.1"
            ],
            "sha256": "be464abbf0e3f375f4865ac2802a6b6d96e7af1ce30984d84f464470cdef17dd",
            "import_time": "2026-06-10T20:19:44.136003474Z",
            "modified_time": "2026-06-10T19:28:13.195865Z",
            "source": "kam193",
            "id": "pypi/2026-06-telegramlite/telegramlite"
        },
        {
            "import_time": "2026-07-09T16:20:49.097350651Z",
            "sha256": "2f68222af052b28841bed7472ec0a37eb4b826d6baa44cd831538a067a9ac054",
            "modified_time": "2026-07-09T15:40:35Z",
            "versions": [
                "1.0.1"
            ],
            "id": "IN-MAL-2026-009184",
            "source": "amazon-inspector"
        },
        {
            "id": "IN-MAL-2026-009182",
            "sha256": "ce1afd32bb4808a41c70c2b9e7d38d36de85eef1ada8d8ae615f5df1a6f88a5c",
            "modified_time": "2026-07-09T15:40:18Z",
            "versions": [
                "1.0.0"
            ],
            "source": "amazon-inspector",
            "import_time": "2026-07-09T16:20:48.916763279Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / telegramlite

Package

Affected ranges

Affected versions

1.*
1.0.0
1.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "package_integrity": [
        {
            "filename": "telegramlite-1.0.1-py3-none-any.whl",
            "hashes": {
                "sha256": "ace355a39f35f9b9c7d074a5b014bb1415ae495839a489515729d6f44a05eac6",
                "blake2b_256": "56294bbc815eda15470489ab22f523eb58e9e0730238e0c4140a4712c05b1a6d",
                "md5": "3228c16ca76b963524b998bbcfd49057"
            }
        },
        {
            "filename": "telegramlite-1.0.1.tar.gz",
            "hashes": {
                "sha256": "adbed80fd97ee185c90597b96f11bc58d149042140619b28cff6e438c1c2cb26",
                "blake2b_256": "b2698eb89376627cc57e48c7ae3bcc2f03ea4677fbc52d7f350a37cbe774181f",
                "md5": "fe5a12f33c4397950ddb65103ef33352"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telegramlite/MAL-2026-5531.json"