MAL-2026-6051

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telegram-lite-grabber/MAL-2026-6051.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-6051
Published
2026-06-17T07:09:46Z
Modified
2026-07-09T16:32:05.805938568Z
Summary
Malicious code in telegram-lite-grabber (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (aad489fe689e441f3237d052bb24702e3178fca26564e662b060c0a8d01fe5f9)

Package is named 'telegram-lite-grabber', a name strongly suggestive of a tool intended to harvest Telegram credentials or session data. No concrete malicious behavior was identified in the scanned files, and no install-time or import-time harmful code paths were observed. The name alone, however, warrants human review to assess whether the package distributes attack tooling, contains a payload not surfaced by automated checks, or is otherwise unsuitable for the registry.

Source: kam193 (70271d13337a92afafb6d5db770a6d73cd960b6910992013d57ec24388ab8fa8)

Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-telegramlite

Reasons (based on the campaign):

  • target:telegram

  • files-exfiltration

Database specific
{
    "iocs": {
        "domains": [
            "telegram-full-server.onrender.com"
        ],
        "urls": [
            "https://telegram-full-server.onrender.com/api/upload"
        ]
    },
    "malicious-packages-origins": [
        {
            "import_time": "2026-06-17T07:59:47.587995782Z",
            "source": "kam193",
            "sha256": "70271d13337a92afafb6d5db770a6d73cd960b6910992013d57ec24388ab8fa8",
            "versions": [
                "1.0.0"
            ],
            "id": "pypi/2026-06-telegramlite/telegram-lite-grabber",
            "modified_time": "2026-06-17T07:09:46.746917Z"
        },
        {
            "import_time": "2026-07-09T16:20:48.818357212Z",
            "modified_time": "2026-07-09T15:40:10Z",
            "sha256": "aad489fe689e441f3237d052bb24702e3178fca26564e662b060c0a8d01fe5f9",
            "versions": [
                "1.0.0"
            ],
            "id": "IN-MAL-2026-009181",
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

PyPI / telegram-lite-grabber

Package

Name
telegram-lite-grabber
View open source insights on deps.dev
Purl
pkg:pypi/telegram-lite-grabber

Affected ranges

Affected versions

1.*
1.0.0

Database specific

indicators
{
    "package_integrity": [
        {
            "filename": "telegram_lite_grabber-1.0.0-py3-none-any.whl",
            "hashes": {
                "sha256": "3cc223f8e8a24d27120a36d1b10929cc14d740bb0ba69e6ff85b03784e48079c",
                "md5": "679672e2cbc3260c35aa8e2f8ea9da32",
                "blake2b_256": "5c822bfd6ead61f3299c0dda532b69dd29faa054ca5e535e60204af3c7954af7"
            }
        },
        {
            "filename": "telegram_lite_grabber-1.0.0.tar.gz",
            "hashes": {
                "md5": "ee798f07895ce403f408dbd7048ff70b",
                "sha256": "bbdea4cc473ada717e0dab5ab390b0232bc9dd0abea188358380c075c06050f9",
                "blake2b_256": "7dabb21d1fe2293c77c679a9570d9f6d2952706095ddfb653a78d131e02d0afe"
            }
        }
    ]
}
cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telegram-lite-grabber/MAL-2026-6051.json"