THREATPKG
SYNC STALE

Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·osv

Malicious code in telegramlite (PyPI)

telegramlite

Risk score

92

AI summary

Indexed incident for telegramlite (pypi).

Description

Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-telegramlite

Reasons (based on the campaign):

  • target:telegram

  • files-exfiltration

Technical details

Affected versions

=1.0.0=1.0.1

Indicators

  • affected version=1.0.075%
  • affected version=1.0.175%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents