Malicious code in telerape (PyPI)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (21e8fc4f3dd969ec103ff1cb8a5bdba0d465bffffabe2615bc38d8e00606cffa) Package places a reverse shell in the PTH file. In analyzed versions, the target was on localhost. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-telerape Reasons (based on the campaign): - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine. - abuses-pth
AI Analysis
Technical Summary
The telerape PyPI package versions 0.0.0.dev0, 1.0.0, and 1.0.1 include embedded code that creates a reverse shell connection to localhost. This functionality allows an attacker to execute arbitrary commands remotely on the affected system. The package is identified as malicious rather than a typical vulnerability, indicating intentional harmful behavior rather than an accidental flaw.
Potential Impact
Systems that install and run the affected versions of the telerape package are at risk of unauthorized remote command execution via the reverse shell. This can lead to full system compromise depending on the privileges of the executing environment. The threat is significant due to the direct control granted to attackers.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately uninstall the telerape package if present and avoid installing it. Use trusted sources and verify package integrity before installation to prevent exposure to malicious packages.
Malicious code in telerape (PyPI)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (21e8fc4f3dd969ec103ff1cb8a5bdba0d465bffffabe2615bc38d8e00606cffa) Package places a reverse shell in the PTH file. In analyzed versions, the target was on localhost. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-telerape Reasons (based on the campaign): - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine. - abuses-pth
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The telerape PyPI package versions 0.0.0.dev0, 1.0.0, and 1.0.1 include embedded code that creates a reverse shell connection to localhost. This functionality allows an attacker to execute arbitrary commands remotely on the affected system. The package is identified as malicious rather than a typical vulnerability, indicating intentional harmful behavior rather than an accidental flaw.
Potential Impact
Systems that install and run the affected versions of the telerape package are at risk of unauthorized remote command execution via the reverse shell. This can lead to full system compromise depending on the privileges of the executing environment. The threat is significant due to the direct control granted to attackers.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately uninstall the telerape package if present and avoid installing it. Use trusted sources and verify package integrity before installation to prevent exposure to malicious packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-11424
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["PyPI"]
Threat ID: 6a6daad3bf32cb7a3466791f
Added to database: 08/01/2026, 08:14:11 UTC
Last enriched: 08/01/2026, 08:20:01 UTC
Last updated: 09/14/2026, 13:31:58 UTC
Views: 43
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.