logo

Pyronut Package Backdoors Telegram Bots With RCE

ID: c04b2e83-d152-5eae-b983-09a96013b32e

STIX ID: report--c04b2e83-d152-5eae-b983-09a96013b32e

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-03-19

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

The report describes 'Pyronut', a malicious PyPI package impersonating the Pyrogram Telegram framework; three malicious versions (2.0.184–2.0.186) were published and rapidly quarantined. Pyronut modifies the pyrogram Client.start() flow to import a hidden backdoor module that registers handlers for remote Python evaluation and shell execution, enabling attackers to execute arbitrary code, steal keys/credentials, and pivot from compromised Telegram bot sessions. Detection and response guidance includes scanning dependency manifests for pyronut, flagging unexpected use of the meval library, checking for Python-spawned /bin/bash -c processes, revoking Telegram tokens, rotating exposed secrets, and rebuilding affected environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.