{"id":"MAL-2026-5531","title":"Malicious code in telegramlite (PyPI)","summary":"Malicious code in telegramlite (PyPI)","severity":"none","vendor":"telegramlite","product":"telegramlite","ecosystem":"pip","affected":["telegramlite"],"published":"2026-06-10","updated":"2026-07-09","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-5531","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/telegramlite"},{"url":"https://pypi.org/project/telegramlite/1.0.1/"},{"url":"https://pypi.org/project/telegramlite/1.0.0/"}],"tags":["osv","pip"],"ingestedAt":"2026-07-09T18:56:35.319Z","slug":"MAL-2026-5531","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ce1afd32bb4808a41c70c2b9e7d38d36de85eef1ada8d8ae615f5df1a6f88a5c)\nNo install-time, import-time, or runtime behaviors of concern were observed in this version. The package name suggests a lightweight Telegram client wrapper, but no code paths matching credential theft, exfiltration, dropper, silent-relay, or backdoor patterns were identified in the scanned files. Routing to human review for name-similarity assessment against established Telegram client libraries before publishing a verdict.\n\n## Source: kam193 (be464abbf0e3f375f4865ac2802a6b6d96e7af1ce30984d84f464470cdef17dd)\nPackage exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-telegramlite\n\n\nReasons (based on the campaign):\n\n\n - target:telegram\n\n\n - files-exfiltration\n\n\n## Affected packages\n\n- `telegramlite`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}