telebot-pro @2.3.8
Vulnerability report · Last retrieved from osv.dev August 12, 2026 at 3:23 AM UTC
OSV ID
MAL-2026-13757
Ecosystem
pypi
Summary
When using the provided bot class, the code starts a hidden exfiltration thread that collects Telegram session files, pictures and information about the machine, like connected WiFi networks. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-telebot-pro Reasons (based on the campaign): - uses-telegram-bot - action-hidden-in-lib-usage - files-exfiltration - target:telegram
Source: kam193 (610b15fa9ed3d59133ac59b1104d43337faddd2ee77eaf21fd238bea6ac4f540)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.