A months-long campaign targeting Python developers has distributed trojanized Pyrogram packages on PyPI, enabling attackers to read arbitrary files and gain control of Telegram bot infrastructure.
Security researchers have identified a coordinated attack leveraging the Python Package Index (PyPI) to distribute malicious versions of Pyrogram, a popular library for building Telegram bots. The campaign, active since November, has successfully compromised developer machines and servers running affected versions.
Attackers created fake Pyrogram forks on PyPI designed to appear legitimate. When developers installed these packages as dependencies, the malicious code executed with server privileges, granting attackers the ability to read sensitive files, exfiltrate credentials, and establish persistent access to bot infrastructure.
The compromised packages contained backdoors that allowed remote code execution. Attackers could retrieve configuration files, API tokens, and database credentials—critical assets for Telegram bot operators. The scope of the campaign suggests multiple malicious packages may have been distributed under similar naming conventions.
PyPI's dependency resolution system made the attack viable. Developers searching for legitimate Pyrogram packages sometimes installed lookalike variants without scrutiny. Once installed, the backdoor code executed during package initialization, before developers could inspect the actual code.
The discovery highlights ongoing supply chain vulnerabilities in open-source ecosystems. While PyPI has removed identified malicious packages, the damage may already be extensive given the campaign's duration and targeting of active developers.
Mitigation steps: Developers should verify package authenticity before installation, review dependency sources, audit bot server logs for unauthorized access, and rotate compromised API tokens and credentials. Organizations running Telegram bots should check their PyPI installation history and audit Pyrogram versions in production environments.
This incident adds to a growing list of PyPI attacks exploiting developer trust in the platform. Security experts recommend implementing software composition analysis tools and restricting package installation to vetted, official sources where possible.
QubesOS released a security update addressing a critical vulnerability that allows arbitrary code execution through an error reporting backchannel in the copy-to-VM function. The flaw affects multiple Qubes versions.
Android devices offer built-in protections against malicious apps, scam calls, and privacy breaches. Activating the correct security settings is essential to maximize these defenses.
File servers remain essential infrastructure for most organizations, but managing access permissions securely grows increasingly complex as systems expand. tenfold Software has outlined five best practices to simplify administration and enforce least-privilege access.
Two Nigerian men have been extradited to the U.S. and charged in connection with sextortion schemes that led to the deaths of two minors in Mississippi and North Carolina.