pypi

telebot-pro @2.3.8

Vulnerability report · Last retrieved from osv.dev August 12, 2026 at 3:23 AM UTC

Malicious

OSV ID

MAL-2026-13757

Ecosystem

pypi

Summary

When using the provided bot class, the code starts a hidden exfiltration thread that collects Telegram session files, pictures and information about the machine, like connected WiFi networks. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-telebot-pro Reasons (based on the campaign): - uses-telegram-bot - action-hidden-in-lib-usage - files-exfiltration - target:telegram

Source: kam193 (610b15fa9ed3d59133ac59b1104d43337faddd2ee77eaf21fd238bea6ac4f540)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.