Pyronut Package Backdoors Telegram Bots With RCE
ID: c04b2e83-d152-5eae-b983-09a96013b32e
STIX ID: report--c04b2e83-d152-5eae-b983-09a96013b32e
Feed Name: GBHackers
The report describes 'Pyronut', a malicious PyPI package impersonating the Pyrogram Telegram framework; three malicious versions (2.0.184–2.0.186) were published and rapidly quarantined. Pyronut modifies the pyrogram Client.start() flow to import a hidden backdoor module that registers handlers for remote Python evaluation and shell execution, enabling attackers to execute arbitrary code, steal keys/credentials, and pivot from compromised Telegram bot sessions. Detection and response guidance includes scanning dependency manifests for pyronut, flagging unexpected use of the meval library, checking for Python-spawned /bin/bash -c processes, revoking Telegram tokens, rotating exposed secrets, and rebuilding affected environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
