{"id":"MAL-2026-16366","title":"Malicious code in pullgetsage (PyPI)","summary":"Malicious code in pullgetsage (PyPI)","severity":"critical","exploited":true,"vendor":"pullgetsage","product":"pullgetsage","ecosystem":"pip","affected":["pullgetsage"],"published":"2026-09-21","updated":"2026-09-21","sourceUpdated":"2026-09-21T20:30:13.717060410Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-16366","references":[{"url":"https://pypi.org/project/pullgetsage/0.1.2/"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-09-22T07:15:17.285Z","slug":"MAL-2026-16366","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (93b751049f78b324983511537b6c053a0ed080639dd7c447d87494eabc134ba3)\nOn import, __init__.py archives the installer's Telegram Desktop tdata directory (%APPDATA%/Telegram Desktop/tdata) into a zip named 'aiosendletter_logs' and POSTs it to a hardcoded Cloudflare Workers endpoint at https://red-poetry-6b6f.martinmcflywork.workers.dev/. The tdata directory holds Telegram session keys; uploading it enables full account takeover of the installer's Telegram account. The behavior is disguised with misleading identifiers ('aiosendletter_logs', 'aioletter initialized') and empty except-block prints that silently swallow errors, and the stated package purpose ('a library filled with books') is unrelated to Telegram.\n\n\n## Affected packages\n\n- `pullgetsage`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}