Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
telegramlitePyPI
Malicious code in telegramlite (PyPI) Remove it immediately and rotate any exposed credentials.
MAL-2026-5531
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall telegramlite
What this malware does
Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-telegramlite
Reasons (based on the campaign):
-
target:telegram
-
files-exfiltration
Malicious versions
1.0.01.0.1
Indicators of compromise (SHA-256)
be464abbf0e3f375f4865ac2802a6b6d96e7af1ce30984d84f464470cdef17dd
Frequently asked questions
No. telegramlite on PyPI has been identified as a malicious package (versions 1.0.0, 1.0.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Campaign
2026-06-telegramlite
References
Credits
- Kamil Mańkowski (kam193) · reporter
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection