logo

Operation Navy Ghost: How Attackers Planted a Telegram-Powered Backdoor Across Fake pyrogram Packages on PyPI

ID: a10c5a0f-1b7c-5411-ba84-383423929493

STIX ID: report--a10c5a0f-1b7c-5411-ba84-383423929493

Feed Name: Checkmarx Zero

Threat Score
90/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Pavan Gudimalla

...
...

**Operation Navy Ghost**: Multiple trojanized pyrogram forks published to PyPI injected a hidden file (pyrogram/helpers/secret.py) that registers Telegram handlers allowing attacker-owned Telegram IDs to run arbitrary Python and shell commands and exfiltrate data via the bot (reply_document). Several packages (vlifegram, vlife-gram, kelragram, pyrogram-navy, pyrogram-styled, sepgram, pyrogram-zeeb, pyrogram-kelra) were found and removed from PyPI; the report provides IOCs (malicious Telegram user IDs and channel), a YARA rule, detection/remediation steps, and advice to rotate credentials and audit affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.