-= Per source details. Do not edit below this line.=-
Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-telegramlite
Reasons (based on the campaign):
target:telegram
files-exfiltration
{
"malicious-packages-origins": [
{
"sha256": "70271d13337a92afafb6d5db770a6d73cd960b6910992013d57ec24388ab8fa8",
"source": "kam193",
"modified_time": "2026-06-17T07:09:46.746917Z",
"versions": [
"1.0.0"
],
"id": "pypi/2026-06-telegramlite/telegram-lite-grabber",
"import_time": "2026-06-17T07:59:47.587995782Z"
}
],
"iocs": {
"domains": [
"telegram-full-server.onrender.com"
],
"urls": [
"https://telegram-full-server.onrender.com/api/upload"
]
}
}