-= Per source details. Do not edit below this line.=-
No install-time, import-time, or runtime behaviors of concern were observed in this version. The package name suggests a lightweight Telegram client wrapper, but no code paths matching credential theft, exfiltration, dropper, silent-relay, or backdoor patterns were identified in the scanned files. Routing to human review for name-similarity assessment against established Telegram client libraries before publishing a verdict.
Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-telegramlite
Reasons (based on the campaign):
target:telegram
files-exfiltration
{
"iocs": {
"urls": [
"https://telegram-full-server.onrender.com/api/upload"
],
"domains": [
"telegram-full-server.onrender.com"
]
},
"malicious-packages-origins": [
{
"versions": [
"1.0.0",
"1.0.1"
],
"sha256": "be464abbf0e3f375f4865ac2802a6b6d96e7af1ce30984d84f464470cdef17dd",
"import_time": "2026-06-10T20:19:44.136003474Z",
"modified_time": "2026-06-10T19:28:13.195865Z",
"source": "kam193",
"id": "pypi/2026-06-telegramlite/telegramlite"
},
{
"import_time": "2026-07-09T16:20:49.097350651Z",
"sha256": "2f68222af052b28841bed7472ec0a37eb4b826d6baa44cd831538a067a9ac054",
"modified_time": "2026-07-09T15:40:35Z",
"versions": [
"1.0.1"
],
"id": "IN-MAL-2026-009184",
"source": "amazon-inspector"
},
{
"id": "IN-MAL-2026-009182",
"sha256": "ce1afd32bb4808a41c70c2b9e7d38d36de85eef1ada8d8ae615f5df1a6f88a5c",
"modified_time": "2026-07-09T15:40:18Z",
"versions": [
"1.0.0"
],
"source": "amazon-inspector",
"import_time": "2026-07-09T16:20:48.916763279Z"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"filename": "telegramlite-1.0.1-py3-none-any.whl",
"hashes": {
"sha256": "ace355a39f35f9b9c7d074a5b014bb1415ae495839a489515729d6f44a05eac6",
"blake2b_256": "56294bbc815eda15470489ab22f523eb58e9e0730238e0c4140a4712c05b1a6d",
"md5": "3228c16ca76b963524b998bbcfd49057"
}
},
{
"filename": "telegramlite-1.0.1.tar.gz",
"hashes": {
"sha256": "adbed80fd97ee185c90597b96f11bc58d149042140619b28cff6e438c1c2cb26",
"blake2b_256": "b2698eb89376627cc57e48c7ae3bcc2f03ea4677fbc52d7f350a37cbe774181f",
"md5": "fe5a12f33c4397950ddb65103ef33352"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telegramlite/MAL-2026-5531.json"