-= Per source details. Do not edit below this line.=-
Package is named 'telegram-lite-grabber', a name strongly suggestive of a tool intended to harvest Telegram credentials or session data. No concrete malicious behavior was identified in the scanned files, and no install-time or import-time harmful code paths were observed. The name alone, however, warrants human review to assess whether the package distributes attack tooling, contains a payload not surfaced by automated checks, or is otherwise unsuitable for the registry.
Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-telegramlite
Reasons (based on the campaign):
target:telegram
files-exfiltration
{
"iocs": {
"domains": [
"telegram-full-server.onrender.com"
],
"urls": [
"https://telegram-full-server.onrender.com/api/upload"
]
},
"malicious-packages-origins": [
{
"import_time": "2026-06-17T07:59:47.587995782Z",
"source": "kam193",
"sha256": "70271d13337a92afafb6d5db770a6d73cd960b6910992013d57ec24388ab8fa8",
"versions": [
"1.0.0"
],
"id": "pypi/2026-06-telegramlite/telegram-lite-grabber",
"modified_time": "2026-06-17T07:09:46.746917Z"
},
{
"import_time": "2026-07-09T16:20:48.818357212Z",
"modified_time": "2026-07-09T15:40:10Z",
"sha256": "aad489fe689e441f3237d052bb24702e3178fca26564e662b060c0a8d01fe5f9",
"versions": [
"1.0.0"
],
"id": "IN-MAL-2026-009181",
"source": "amazon-inspector"
}
]
}{
"package_integrity": [
{
"filename": "telegram_lite_grabber-1.0.0-py3-none-any.whl",
"hashes": {
"sha256": "3cc223f8e8a24d27120a36d1b10929cc14d740bb0ba69e6ff85b03784e48079c",
"md5": "679672e2cbc3260c35aa8e2f8ea9da32",
"blake2b_256": "5c822bfd6ead61f3299c0dda532b69dd29faa054ca5e535e60204af3c7954af7"
}
},
{
"filename": "telegram_lite_grabber-1.0.0.tar.gz",
"hashes": {
"md5": "ee798f07895ce403f408dbd7048ff70b",
"sha256": "bbdea4cc473ada717e0dab5ab390b0232bc9dd0abea188358380c075c06050f9",
"blake2b_256": "7dabb21d1fe2293c77c679a9570d9f6d2952706095ddfb653a78d131e02d0afe"
}
}
]
}
[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telegram-lite-grabber/MAL-2026-6051.json"