---
id: MAL-2026-6051
title: Malicious code in telegram-lite-grabber (PyPI)
summary: Malicious code in telegram-lite-grabber (PyPI)
severity: none
vendor: telegram-lite-grabber
product: telegram-lite-grabber
ecosystem: pip
affected:
  - telegram-lite-grabber
published: '2026-06-17'
updated: '2026-07-09'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-6051'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/telegram-lite-grabber'
  - url: 'https://pypi.org/project/telegram-lite-grabber/1.0.0/'
tags:
  - osv
  - pip
ingestedAt: '2026-07-09T18:56:35.323Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (aad489fe689e441f3237d052bb24702e3178fca26564e662b060c0a8d01fe5f9)
Package is named 'telegram-lite-grabber', a name strongly suggestive of a tool intended to harvest Telegram credentials or session data. No concrete malicious behavior was identified in the scanned files, and no install-time or import-time harmful code paths were observed. The name alone, however, warrants human review to assess whether the package distributes attack tooling, contains a payload not surfaced by automated checks, or is otherwise unsuitable for the registry.

## Source: kam193 (70271d13337a92afafb6d5db770a6d73cd960b6910992013d57ec24388ab8fa8)
Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-06-telegramlite


Reasons (based on the campaign):


 - target:telegram


 - files-exfiltration


## Affected packages

- `telegram-lite-grabber`

## Remediation

Refer to the advisory for the patched release.
