Logo
pypi

pullgetsage@0.1.2

Vulnerability report · Last retrieved from osv.dev September 21, 2026 at 11:45 PM UTC

Malicious

OSV ID

MAL-2026-16366

Ecosystem

pypi

Summary

On import, __init__.py archives the installer's Telegram Desktop tdata directory (%APPDATA%/Telegram Desktop/tdata) into a zip named 'aiosendletter_logs' and POSTs it to a hardcoded Cloudflare Workers endpoint at https://red-poetry-6b6f.martinmcflywork.workers.dev/. The tdata directory holds Telegram session keys; uploading it enables full account takeover of the installer's Telegram account. The behavior is disguised with misleading identifiers ('aiosendletter_logs', 'aioletter initialized') and empty except-block prints that silently swallow errors, and the stated package purpose ('a library filled with books') is unrelated to Telegram.

Source: amazon-inspector (93b751049f78b324983511537b6c053a0ed080639dd7c447d87494eabc134ba3)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.