MAL-2026-10863
Malicious code in telebot-bot-run (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (3427c3bade820197fefbdc26a5be82d8feeca5f96d35cf035aab848167f2df26) The package, distinguished as a speed testing or typosquatted Telegram library, contains a Telegram bot to perform remote control of the computer
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-10-speedd-testing-bot
Reasons (based on the campaign):
- typosquatting
- Downloads and executes a remote malicious script.
- rat
## Source: ossf-package-analysis (956d172026e3ec8ca278acca488473700f3d28483adf026901c3fcc06f501972) The OpenSSF Package Analysis project identified 'telebot-bot-run' @ 0.5 (pypi) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
- The package executes one or more commands associated with malicious behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for telebot-bot-run (pip). Pin to a known-safe version or switch to an alternative.