MAL-2026-6560

    Dashboard / Malicious Package / MAL-2026-6560

    MAL-2026-6560

    Published: 28 Jun 2026Last Modified: 29 Jun 2026

    Summary: Malicious code in tdata-grabber (PyPI)

    Details: Source: amazon-inspector (9b4c3b37df5e3d08d7bc6ad736e0231ed0dc655640ffdf0dc403f4029ace2787) Package name explicitly declares its purpose as harvesting Telegram Desktop session data (tdata directory). The tdata folder contains live authenticated Telegram session keys; collecting and exfiltrating it enables full account takeover of the installer's Telegram account by whoever receives the data. Automated tracing of the package contents engaged but its output was withheld by the provider's malware-content safety filter — a signal consistent with the file contents reading as operational session-stealer code. Combined with the self-declared purpose in the package name, the package fits the messaging-session-theft fingerprint (active-attack) rather than any legitimate library shape. Source: kam193 (6aa5184e991d29d6a751e13971ce2ce6a1cec834f675a1c3dd5eb0fc2ec75762) Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-telegramlite Reasons (based on the campaign): - target:telegram - files-exfiltration

    Affected packages

    Package

    Name: tdata-grabber

    Purl: pkg:pypi/tdata-grabber

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    1.0.0