MAL-2025-191674

    Dashboard / Malicious Package / MAL-2025-191674

    MAL-2025-191674

    Published: 22 Nov 2025Last Modified: 19 Mar 2026

    Summary: Malicious code in aiogram-msgeffect (PyPI)

    Details: Source: kam193 (edd5a99e6d1cebb47e713991f08b50dee4b5bf93ae487f6adc446318ccdba6e7) Importing the module starts obfuscated code which then look for data related to some Telegram clients and attempt to exfiltrate them Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-11-tgeffect Reasons (based on the campaign): - obfuscation - target:telegram - exfiltration-credentials

    Affected packages

    Package

    Name: aiogram-msgeffect

    Purl: pkg:pypi/aiogram-msgeffect

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.2.1
    MAL-2025-191674 | CVE-DB