VDB
Sign up

MAL-2026-16017

Malicious code in telegram-helper (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (7db7944f424aaa877ab4c7d4555c4358900d45011b05a886837a14efea2a72a9) The package hides code that starts a Telegram bot to exfiltrate sensitive session files and cookies

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-telegram-helper

Reasons (based on the campaign):

- The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

- rat

- files-exfiltration

- target:telegram

- uses-telegram-bot

- exfiltration-browser-data

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/telegram-helper

No fixed version published yet for telegram-helper (pip). Pin to a known-safe version or switch to an alternative.

References