MAL-2026-5531

    Dashboard / Malicious Package / MAL-2026-5531

    MAL-2026-5531

    Published: 10 Jun 2026Last Modified: 9 Jul 2026

    Summary: Malicious code in telegramlite (PyPI)

    Details: Source: amazon-inspector (ce1afd32bb4808a41c70c2b9e7d38d36de85eef1ada8d8ae615f5df1a6f88a5c) No install-time, import-time, or runtime behaviors of concern were observed in this version. The package name suggests a lightweight Telegram client wrapper, but no code paths matching credential theft, exfiltration, dropper, silent-relay, or backdoor patterns were identified in the scanned files. Routing to human review for name-similarity assessment against established Telegram client libraries before publishing a verdict. Source: kam193 (be464abbf0e3f375f4865ac2802a6b6d96e7af1ce30984d84f464470cdef17dd) Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-telegramlite Reasons (based on the campaign): - target:telegram - files-exfiltration

    Affected packages

    Package

    Name: telegramlite

    Purl: pkg:pypi/telegramlite

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    1.0.1
    MAL-2026-5531 | CVE-DB