pullgetsage@0.1.2
Vulnerability report · Last retrieved from osv.dev September 21, 2026 at 11:45 PM UTC
OSV ID
MAL-2026-16366
Ecosystem
pypi
Summary
On import, __init__.py archives the installer's Telegram Desktop tdata directory (%APPDATA%/Telegram Desktop/tdata) into a zip named 'aiosendletter_logs' and POSTs it to a hardcoded Cloudflare Workers endpoint at https://red-poetry-6b6f.martinmcflywork.workers.dev/. The tdata directory holds Telegram session keys; uploading it enables full account takeover of the installer's Telegram account. The behavior is disguised with misleading identifiers ('aiosendletter_logs', 'aioletter initialized') and empty except-block prints that silently swallow errors, and the stated package purpose ('a library filled with books') is unrelated to Telegram.
Source: amazon-inspector (93b751049f78b324983511537b6c053a0ed080639dd7c447d87494eabc134ba3)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.