VYPR

pypi · Malicious package advisory

Malware

telegram-lite-grabber

MAL-2026-6051

Malicious code in telegram-lite-grabber (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (aad489fe689e441f3237d052bb24702e3178fca26564e662b060c0a8d01fe5f9)
Package is named 'telegram-lite-grabber', a name strongly suggestive of a tool intended to harvest Telegram credentials or session data. No concrete malicious behavior was identified in the scanned files, and no install-time or import-time harmful code paths were observed. The name alone, however, warrants human review to assess whether the package distributes attack tooling, contains a payload not surfaced by automated checks, or is otherwise unsuitable for the registry.

## Source: kam193 (70271d13337a92afafb6d5db770a6d73cd960b6910992013d57ec24388ab8fa8)
Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-06-telegramlite


Reasons (based on the campaign):


 - target:telegram


 - files-exfiltration

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.