-= Per source details. Do not edit below this line.=-
Package contains a Telegram bot for remote control of the machine. While this doesn't start automatically, this behavior is not disclosed by the package description
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-02-khelo
Reasons (based on the campaign):
rat
The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.
{
"malicious-packages-origins": [
{
"modified_time": "2026-02-08T22:19:04.039326Z",
"versions": [
"1.0.0"
],
"sha256": "8090b17ada40e394e1d9df27c6fe6c22db7eed330f00e44ee1cc4d94bfbf3fef",
"id": "pypi/2026-02-khelo/teligram",
"source": "kam193",
"import_time": "2026-02-08T22:44:59.227180464Z"
}
]
}