{"id":"MAL-2026-16366","summary":"Malicious code in pullgetsage (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (93b751049f78b324983511537b6c053a0ed080639dd7c447d87494eabc134ba3)\nOn import, __init__.py archives the installer's Telegram Desktop tdata directory (%APPDATA%/Telegram Desktop/tdata) into a zip named 'aiosendletter_logs' and POSTs it to a hardcoded Cloudflare Workers endpoint at https://red-poetry-6b6f.martinmcflywork.workers.dev/. The tdata directory holds Telegram session keys; uploading it enables full account takeover of the installer's Telegram account. The behavior is disguised with misleading identifiers ('aiosendletter_logs', 'aioletter initialized') and empty except-block prints that silently swallow errors, and the stated package purpose ('a library filled with books') is unrelated to Telegram.\n","modified":"2026-09-21T20:30:11.494219068Z","published":"2026-09-21T19:43:02Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["0.1.2"],"id":"IN-MAL-2026-020272","import_time":"2026-09-21T20:17:15.445044016Z","modified_time":"2026-09-21T19:43:02Z","sha256":"93b751049f78b324983511537b6c053a0ed080639dd7c447d87494eabc134ba3"}]},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/pullgetsage/0.1.2/"}],"affected":[{"package":{"name":"pullgetsage","ecosystem":"PyPI","purl":"pkg:pypi/pullgetsage"},"versions":["0.1.2"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"0631314aac421051a0b5ab5c8c2099d8f715e3b36f625043babc53601ff5e73bbb0299","path":"pullgetsage/__init__.py","sha256":"f070c5e1dea20964db8df00cea65238df33b0ec9acbf74c0ff8e9b86a886c2aa"}],"package_integrity":[{"filename":"pullgetsage-0.1.2-py3-none-any.whl","hashes":{"blake2b_256":"3a62f211f5bfcf68163380231c485a97d97348780f55922494b34a0169526b81","md5":"a6733ea23e2aa8319a21e3694456d1d9","sha256":"b1ff9962b581dc798ad21641243404c0089043f34159223b96e89d4b797cad26"}},{"filename":"pullgetsage-0.1.2.tar.gz","hashes":{"sha256":"19ef9c9b990696ea0d8b8574b6b3d55956a8fe2df3fa21810cfd02370bb889a3","blake2b_256":"88a357bcf02d1d07b51182b487cbf18a3feb8eca0bbfa35570a4fd6d3261dc8f","md5":"c943a8965bfcea9ab9fda9ed59be2e04"}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/pullgetsage/MAL-2026-16366.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}