---
id: MAL-2026-16366
title: Malicious code in pullgetsage (PyPI)
summary: Malicious code in pullgetsage (PyPI)
severity: critical
exploited: true
vendor: pullgetsage
product: pullgetsage
ecosystem: pip
affected:
  - pullgetsage
published: '2026-09-21'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T05:30:07.556312536Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-16366'
references:
  - url: 'https://pypi.org/project/pullgetsage/0.1.2/'
  - url: 'https://bad-packages.kam193.eu/pypi/package/pullgetsage'
  - url: 'https://pypi.org/project/pullgetsage/0.1.0/'
  - url: 'https://pypi.org/project/pullgetsage/0.1.1/'
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-09-22T07:15:17.285Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (93b751049f78b324983511537b6c053a0ed080639dd7c447d87494eabc134ba3)
On import, __init__.py archives the installer's Telegram Desktop tdata directory (%APPDATA%/Telegram Desktop/tdata) into a zip named 'aiosendletter_logs' and POSTs it to a hardcoded Cloudflare Workers endpoint at https://red-poetry-6b6f.martinmcflywork.workers.dev/. The tdata directory holds Telegram session keys; uploading it enables full account takeover of the installer's Telegram account. The behavior is disguised with misleading identifiers ('aiosendletter_logs', 'aioletter initialized') and empty except-block prints that silently swallow errors, and the stated package purpose ('a library filled with books') is unrelated to Telegram.

## Source: kam193 (5a4369fbf36c4c2a54c7555febeaf8fda122d33a7ba9b9d11e77031849f5c7d8)
Package hides code to exfiltrate files. Most releases target unclear files, but some reveal the goal to exfiltrate sensitive Telegram data.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-aiosendletter


Reasons (based on the campaign):


 - files-exfiltration


 - target:telegram


## Affected packages

- `pullgetsage`

## Remediation

Refer to the advisory for the patched release.
