Operation Navy Ghost: How Attackers Planted a Telegram-Powered Backdoor Across Fake pyrogram Packages on PyPI
ID: a10c5a0f-1b7c-5411-ba84-383423929493
STIX ID: report--a10c5a0f-1b7c-5411-ba84-383423929493
Feed Name: Checkmarx Zero
**Operation Navy Ghost**: Multiple trojanized pyrogram forks published to PyPI injected a hidden file (pyrogram/helpers/secret.py) that registers Telegram handlers allowing attacker-owned Telegram IDs to run arbitrary Python and shell commands and exfiltrate data via the bot (reply_document). Several packages (vlifegram, vlife-gram, kelragram, pyrogram-navy, pyrogram-styled, sepgram, pyrogram-zeeb, pyrogram-kelra) were found and removed from PyPI; the report provides IOCs (malicious Telegram user IDs and channel), a YARA rule, detection/remediation steps, and advice to rotate credentials and audit affected systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
