{"id":"MAL-2026-6051","title":"Malicious code in telegram-lite-grabber (PyPI)","summary":"Malicious code in telegram-lite-grabber (PyPI)","severity":"none","vendor":"telegram-lite-grabber","product":"telegram-lite-grabber","ecosystem":"pip","affected":["telegram-lite-grabber"],"published":"2026-06-17","updated":"2026-07-09","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-6051","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/telegram-lite-grabber"},{"url":"https://pypi.org/project/telegram-lite-grabber/1.0.0/"}],"tags":["osv","pip"],"ingestedAt":"2026-07-09T18:56:35.323Z","slug":"MAL-2026-6051","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (aad489fe689e441f3237d052bb24702e3178fca26564e662b060c0a8d01fe5f9)\nPackage is named 'telegram-lite-grabber', a name strongly suggestive of a tool intended to harvest Telegram credentials or session data. No concrete malicious behavior was identified in the scanned files, and no install-time or import-time harmful code paths were observed. The name alone, however, warrants human review to assess whether the package distributes attack tooling, contains a payload not surfaced by automated checks, or is otherwise unsuitable for the registry.\n\n## Source: kam193 (70271d13337a92afafb6d5db770a6d73cd960b6910992013d57ec24388ab8fa8)\nPackage exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-telegramlite\n\n\nReasons (based on the campaign):\n\n\n - target:telegram\n\n\n - files-exfiltration\n\n\n## Affected packages\n\n- `telegram-lite-grabber`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}