VDB
KO

MAL-2026-13757

Malicious code in telebot-pro (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (610b15fa9ed3d59133ac59b1104d43337faddd2ee77eaf21fd238bea6ac4f540) When using the provided bot class, the code starts a hidden exfiltration thread that collects Telegram session files, pictures and information about the machine, like connected WiFi networks.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-08-telebot-pro

Reasons (based on the campaign):

- uses-telegram-bot

- action-hidden-in-lib-usage

- files-exfiltration

- target:telegram

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / telebot-pro

No fixed version published yet for telebot-pro (pip). Pin to a known-safe version or switch to an alternative.

References