Malicious code in telegram-helper (PyPI)
The PyPI package 'telegram-helper' versions 0.1.1 and 0.1.2 contain malicious code that starts a Telegram bot to exfiltrate sensitive session files and browser cookies. This package acts as a remote access trojan (RAT) with capabilities to execute remote commands and steal browser data. It is designed to target victims via Telegram and uses a Telegram bot for command and control and data exfiltration.
AI Analysis
Technical Summary
The 'telegram-helper' package on PyPI, specifically versions 0.1.1 and 0.1.2, contains hidden malicious code that initiates a Telegram bot to exfiltrate sensitive session files and browser cookies from the victim's machine. The package includes functionality to execute remote commands, likely limited to a specific set, effectively acting as a remote access trojan (RAT). Its primary targets are Telegram users, leveraging the Telegram bot infrastructure for command and control and data exfiltration. This campaign is categorized as malicious with clear intent to steal information.
Potential Impact
The malicious package can lead to unauthorized remote command execution on the victim's machine and exfiltration of sensitive data such as session files and browser cookies. This compromises user privacy and security, potentially allowing attackers to hijack sessions or access sensitive accounts. There is no indication of active exploitation in the wild yet.
Mitigation Recommendations
Users should immediately uninstall the 'telegram-helper' package versions 0.1.1 and 0.1.2 if installed. Avoid using this package from PyPI as it contains malicious code. Since no official patch or fix is available, the best mitigation is to remove the package and monitor for any suspicious activity. Verify dependencies and sources before installing Python packages.
Malicious code in telegram-helper (PyPI)
Description
The PyPI package 'telegram-helper' versions 0.1.1 and 0.1.2 contain malicious code that starts a Telegram bot to exfiltrate sensitive session files and browser cookies. This package acts as a remote access trojan (RAT) with capabilities to execute remote commands and steal browser data. It is designed to target victims via Telegram and uses a Telegram bot for command and control and data exfiltration.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'telegram-helper' package on PyPI, specifically versions 0.1.1 and 0.1.2, contains hidden malicious code that initiates a Telegram bot to exfiltrate sensitive session files and browser cookies from the victim's machine. The package includes functionality to execute remote commands, likely limited to a specific set, effectively acting as a remote access trojan (RAT). Its primary targets are Telegram users, leveraging the Telegram bot infrastructure for command and control and data exfiltration. This campaign is categorized as malicious with clear intent to steal information.
Potential Impact
The malicious package can lead to unauthorized remote command execution on the victim's machine and exfiltration of sensitive data such as session files and browser cookies. This compromises user privacy and security, potentially allowing attackers to hijack sessions or access sensitive accounts. There is no indication of active exploitation in the wild yet.
Defensive Guidance
Users should immediately uninstall the 'telegram-helper' package versions 0.1.1 and 0.1.2 if installed. Avoid using this package from PyPI as it contains malicious code. Since no official patch or fix is available, the best mitigation is to remove the package and monitor for any suspicious activity. Verify dependencies and sources before installing Python packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-16017
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a9f9111acd9273b49ff2b5d
Added to database: 09/08/2026, 04:37:37 UTC
Last enriched: 09/08/2026, 05:09:15 UTC
Last updated: 09/08/2026, 10:09:44 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.