mal-2026-16366
ossf_malicious_packages--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (93b751049f78b324983511537b6c053a0ed080639dd7c447d87494eabc134ba3) On import, __init__.py archives the installer's Telegram Desktop tdata directory (%APPDATA%/Telegram Desktop/tdata) into a zip named 'aiosendletter_logs' and POSTs it to a hardcoded Cloudflare Workers endpoint at https://red-poetry-6b6f.martinmcflywork.workers.dev/. The tdata directory holds Telegram session keys; uploading it enables full account takeover of the installer's Telegram account. The behavior is disguised with misleading identifiers ('aiosendletter_logs', 'aioletter initialized') and empty except-block prints that silently swallow errors, and the stated package purpose ('a library filled with books') is unrelated to Telegram. ## Source: kam193 (5a4369fbf36c4c2a54c7555febeaf8fda122d33a7ba9b9d11e77031849f5c7d8) Package hides code to exfiltrate files. Most releases target unclear files, but some reveal the goal to exfiltrate sensitive Telegram data. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-aiosendletter Reasons (based on the campaign): - files-exfiltration - target:telegram
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No linked vulnerabilities found.
{
"affected": [
{
"database_specific": {
"cwes": [
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
],
"indicators": {
"evidence_files": [
{
"path": "pullgetsage/__init__.py",
"sha256": "f070c5e1dea20964db8df00cea65238df33b0ec9acbf74c0ff8e9b86a886c2aa",
"tlsh": "0631314aac421051a0b5ab5c8c2099d8f715e3b36f625043babc53601ff5e73bbb0299"
}
],
"package_integrity": [
{
"filename": "pullgetsage-0.1.2-py3-none-any.whl",
"hashes": {
"blake2b_256": "3a62f211f5bfcf68163380231c485a97d97348780f55922494b34a0169526b81",
"md5": "a6733ea23e2aa8319a21e3694456d1d9",
"sha256": "b1ff9962b581dc798ad21641243404c0089043f34159223b96e89d4b797cad26"
}
},
{
"filename": "pullgetsage-0.1.2.tar.gz",
"hashes": {
"blake2b_256": "88a357bcf02d1d07b51182b487cbf18a3feb8eca0bbfa35570a4fd6d3261dc8f",
"md5": "c943a8965bfcea9ab9fda9ed59be2e04",
"sha256": "19ef9c9b990696ea0d8b8574b6b3d55956a8fe2df3fa21810cfd02370bb889a3"
}
}
]
}
},
"package": {
"ecosystem": "PyPI",
"name": "pullgetsage"
},
"versions": [
"0.1.2",
"0.1.0",
"0.1.1"
]
}
],
"credits": [
{
"contact": [
"inspector-research@amazon.com"
],
"name": "Amazon Inspector",
"type": "FINDER"
},
{
"contact": [
"https://github.com/kam193",
"https://bad-packages.kam193.eu/"
],
"name": "Kamil Mańkowski (kam193)",
"type": "ANALYST"
}
],
"database_specific": {
"iocs": {
"domains": [
"sparkling-pine-f202.stilluer-sweden.workers.dev",
"red-poetry-6b6f.martinmcflywork.workers.dev"
]
},
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020272",
"import_time": "2026-09-21T20:17:15.445044016Z",
"modified_time": "2026-09-21T19:43:02Z",
"sha256": "93b751049f78b324983511537b6c053a0ed080639dd7c447d87494eabc134ba3",
"source": "amazon-inspector",
"versions": [
"0.1.2"
]
},
{
"id": "pypi/2026-09-aiosendletter/pullgetsage",
"import_time": "2026-09-22T23:15:47.70738285Z",
"modified_time": "2026-09-22T22:34:33.280798Z",
"sha256": "5a4369fbf36c4c2a54c7555febeaf8fda122d33a7ba9b9d11e77031849f5c7d8",
"source": "kam193",
"versions": [
"0.1.0",
"0.1.1",
"0.1.2"
]
},
{
"id": "IN-MAL-2026-020465",
"import_time": "2026-09-23T05:18:36.531876266Z",
"modified_time": "2026-09-23T05:11:10Z",
"sha256": "a8681b3c6d6950321d2104c5f744bdcb237baaa3b855a1f40ecf61aac3f59a7b",
"source": "amazon-inspector",
"versions": [
"0.1.0"
]
},
{
"id": "IN-MAL-2026-020466",
"import_time": "2026-09-23T05:18:36.680225379Z",
"modified_time": "2026-09-23T05:11:20Z",
"sha256": "87b03140924cb064b6229747c68b2b2dfc34c09a2790af5bbe09946009d7c3e4",
"source": "amazon-inspector",
"versions": [
"0.1.1"
]
}
]
},
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (93b751049f78b324983511537b6c053a0ed080639dd7c447d87494eabc134ba3)\nOn import, __init__.py archives the installer's Telegram Desktop tdata directory (%APPDATA%/Telegram Desktop/tdata) into a zip named 'aiosendletter_logs' and POSTs it to a hardcoded Cloudflare Workers endpoint at https://red-poetry-6b6f.martinmcflywork.workers.dev/. The tdata directory holds Telegram session keys; uploading it enables full account takeover of the installer's Telegram account. The behavior is disguised with misleading identifiers ('aiosendletter_logs', 'aioletter initialized') and empty except-block prints that silently swallow errors, and the stated package purpose ('a library filled with books') is unrelated to Telegram.\n\n## Source: kam193 (5a4369fbf36c4c2a54c7555febeaf8fda122d33a7ba9b9d11e77031849f5c7d8)\nPackage hides code to exfiltrate files. Most releases target unclear files, but some reveal the goal to exfiltrate sensitive Telegram data.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-aiosendletter\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n\n\n - target:telegram\n",
"id": "MAL-2026-16366",
"modified": "2026-09-23T05:20:43.649661339Z",
"published": "2026-09-21T19:43:02Z",
"references": [
{
"type": "PACKAGE",
"url": "https://pypi.org/project/pullgetsage/0.1.2/"
},
{
"type": "WEB",
"url": "https://bad-packages.kam193.eu/pypi/package/pullgetsage"
},
{
"type": "PACKAGE",
"url": "https://pypi.org/project/pullgetsage/0.1.0/"
},
{
"type": "PACKAGE",
"url": "https://pypi.org/project/pullgetsage/0.1.1/"
}
],
"schema_version": "1.7.4",
"summary": "Malicious code in pullgetsage (PyPI)"
}