VDB
KO

MAL-2026-10863

Malicious code in telebot-bot-run (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (3427c3bade820197fefbdc26a5be82d8feeca5f96d35cf035aab848167f2df26) The package, distinguished as a speed testing or typosquatted Telegram library, contains a Telegram bot to perform remote control of the computer

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-10-speedd-testing-bot

Reasons (based on the campaign):

- typosquatting

- Downloads and executes a remote malicious script.

- rat

## Source: ossf-package-analysis (956d172026e3ec8ca278acca488473700f3d28483adf026901c3fcc06f501972) The OpenSSF Package Analysis project identified 'telebot-bot-run' @ 0.5 (pypi) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

- The package executes one or more commands associated with malicious behavior.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / telebot-bot-run

No fixed version published yet for telebot-bot-run (pip). Pin to a known-safe version or switch to an alternative.

References