Malicious code in telebot-pro (PyPI)
Malware
Published
Aug 11, 2026
to the GitHub Advisory Database
Description
Published to the GitHub Advisory Database
Aug 11, 2026
Reviewed
Aug 11, 2026
Source: kam193 (610b15fa9ed3d59133ac59b1104d43337faddd2ee77eaf21fd238bea6ac4f540)
When using the provided bot class, the code starts a hidden exfiltration thread that collects Telegram session files, pictures and information about the machine, like connected WiFi networks.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-telebot-pro
Reasons (based on the campaign):
uses-telegram-bot
action-hidden-in-lib-usage
files-exfiltration
target:telegram
Credit: OpenSSF (source)
References