MAL-2026-16017
Malicious code in telegram-helper (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (7db7944f424aaa877ab4c7d4555c4358900d45011b05a886837a14efea2a72a9) The package hides code that starts a Telegram bot to exfiltrate sensitive session files and cookies
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-telegram-helper
Reasons (based on the campaign):
- The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.
- rat
- files-exfiltration
- target:telegram
- uses-telegram-bot
- exfiltration-browser-data
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for telegram-helper (pip). Pin to a known-safe version or switch to an alternative.