pypi
Malicious tdata-grabber @1.0.0
Vulnerability report · Last retrieved from osv.dev June 28, 2026 at 11:54 PM UTC
OSV ID
MAL-2026-6560
Ecosystem
pypi
Summary
Package exfiltrates data from the Telegram application to a remote location, effectively collecting Telegram sessions. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-telegramlite Reasons (based on the campaign): - target:telegram - files-exfiltration
Source: kam193 (6aa5184e991d29d6a751e13971ce2ce6a1cec834f675a1c3dd5eb0fc2ec75762)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.