MAL-2026-13757
Malicious code in telebot-pro (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (610b15fa9ed3d59133ac59b1104d43337faddd2ee77eaf21fd238bea6ac4f540) When using the provided bot class, the code starts a hidden exfiltration thread that collects Telegram session files, pictures and information about the machine, like connected WiFi networks.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-telebot-pro
Reasons (based on the campaign):
- uses-telegram-bot
- action-hidden-in-lib-usage
- files-exfiltration
- target:telegram
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for telebot-pro (pip). Pin to a known-safe version or switch to an alternative.