logo

Malicious ‘Pyronut’ Package Backdoors Telegram Bots With Remote Code Execution

ID: 266c1a64-42a5-56cc-9135-98cd2052fd3c

STIX ID: report--266c1a64-42a5-56cc-9135-98cd2052fd3c

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive Summary:** A malicious PyPI package called `pyronut` posed as the pyrogram framework and contained a hidden runtime backdoor (pyrogram/helpers/secret.py) that activated on Client.start(), registering Telegram handlers that allowed arbitrary Python execution and shell command execution; three malicious versions (2.0.184–2.0.186) were published on 2026-03-18 and quarantined the same day, but any developers who executed the package were at risk of credential theft, data exfiltration, and full Telegram session compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.