Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Part of a larger attack: 2025-10-speedd-testing-bot published 26 malicious packages. See the full campaign →
Malicious package

telebot-bot-runPyPI

telebot-bot-run is a confirmed malicious PyPI package (MAL-2026-10863) that steals credentials and exfiltrates sensitive data (malicious versions 0.3, 0.4, 0.5). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in telebot-bot-run (PyPI)

MAL-2026-10863
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall telebot-bot-run

What this malware does

On import, telebot-bot-run 0.3 executes two attacker-controlled code paths against the installer's host. First, the top-level module fetches https://pastebin.com/raw/xAT1vudj via requests.get and passes the response body directly to exec(), running whatever Python the anonymous, mutable Pastebin URL currently serves under the installer's process. Second, the module hardcodes a Telegram bot token (8951969280:...) and auto-starts an infinity_polling thread that registers handlers /ssh, /get, /collect, /del, /make, and an upload handler. The /ssh handler runs attacker-supplied strings through subprocess.run with shell=True; /get sends any file path on the host to the Telegram chat via bot.send_document; /collect zips any directory with shutil.make_archive and uploads the archive; /start re-fetches the same Pastebin URL and pipes it into python3 as a detached background process for persistence. The package's setup.py metadata (author='fuckkkkk you 2 3 4', description='Simple Scopper Library') is consistent with the observed behavior rather than a legitimate telebot helper.

The package, distinguished as a speed testing or typosquatted Telegram library, contains a Telegram bot to perform remote control of the computer

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-10-speedd-testing-bot

Reasons (based on the campaign):

  • typosquatting

  • Downloads and executes a remote malicious script.

  • rat

The OpenSSF Package Analysis project identified 'telebot-bot-run' @ 0.5 (pypi) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Malicious versions

3 flagged
0.30.40.5

Indicators of compromise (SHA-256)

956d172026e3ec8ca278acca488473700f3d28483adf026901c3fcc06f501972
3427c3bade820197fefbdc26a5be82d8feeca5f96d35cf035aab848167f2df26
95c556b9ded1648a2523210bf518dea35324c749733eabeef3268795351b1b9c
471d5e59aa7805d8ab169edeee746470f077d1daaebcf14f45376513fe53ae22
dc53581e311e31116c859ea7df64f589623b6b854f292990e0d8bb3fd460c058

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for telebot-bot-run (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging telebot-bot-run across your stack and pipelines.

  2. If you installed it — respond

    telebot-bot-run is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If telebot-bot-run was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks telebot-bot-run before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. telebot-bot-run on PyPI has been identified as a malicious package (versions 0.3, 0.4, 0.5 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2025-10-speedd-testing-botIN-MAL-2026-010802IN-MAL-2026-010852IN-MAL-2026-010850

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter
  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks telebot-bot-run-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

telebot-bot-run (PyPI) malicious package — MAL-2026-10863 | O3 Security