# Supply Chain Attack: Malicious PyPI Packages Targeting Telegram Bot Developers


A sophisticated supply chain campaign has been quietly compromising Python developers since November 2025, with attackers publishing at least eight trojanized packages on PyPI designed to give complete control of Telegram bot servers to remote threat actors. Security researchers at Checkmarx have dubbed the campaign Operation Navy Ghost, revealing a coordinated effort that exploits the continued popularity of the deprecated Pyrogram library—despite no longer being actively maintained.


## The Threat: A Hidden Backdoor in Plain Sight


Between November 2025 and June 2026, the threat actor published multiple malicious Pyrogram forks under different package names on the Python Package Index. Each contained identical backdoor functionality hidden within a file called secret.py, buried in the helpers module. The sophistication lies in its timing: the backdoor activates silently when an infected bot launches, registering hidden Telegram command handlers that remain invisible to standard monitoring.


The compromised packages include:


  • pyrogram-styled (16+ versions, 15,370 downloads)
  • VLifeGram (9 versions, 4,150 downloads)
  • pyrogram-navy (6 versions, 2,530 downloads)
  • VLife-Gram (5 versions, 1,030 downloads)
  • kelragram (3 versions, 1,041 downloads)
  • pyrogram-zeeb (1 version, 432 downloads)
  • pyrogram-kelra (1 version, 672 downloads)
  • sepgram (1 version, 264 downloads)

  • Across all packages, the campaign achieved an estimated 25,000+ downloads, though Checkmarx notes this likely underrepresents actual infection since automated systems and CI/CD pipelines may have pulled additional versions.


    ## Technical Details: How the Backdoor Works


    The malware employs a two-pronged attack mechanism designed specifically to exploit the capabilities of Telegram bot clients.


    Remote Code Execution (RCE): When the attacker sends the command /asu print(os.environ) to the infected bot, the backdoor compiles and executes arbitrary Python code on the victim's server. This gives attackers full access to environment variables, which frequently contain API keys, database credentials, and cloud service tokens.


    Shell Command Execution: The /asi command permits attackers to execute arbitrary shell commands with the privileges of the infected application. A simple cat /etc/passwd command demonstrates the exposure—any system file, database backup, or credential store becomes readable to the attacker.


    Command output under 4,096 bytes is returned directly via Telegram messages. Larger outputs are transmitted as document attachments, allowing exfiltration of entire databases or configuration files.


    Persistence and Stealth:


    The backdoor contains a hardcoded list of Telegram IDs designated as "OWNERS"—only these specific accounts can issue commands to the compromised bot. This design:


  • Prevents accidental discovery by developers testing their own bots
  • Creates a direct command-and-control channel independent of traditional infrastructure
  • Allows the attacker to deactivate the backdoor on their own test systems
  • Operates silently, suppressing all errors and disabling logging functions

  • The malware deliberately targets production Telegram bot accounts, not development environments. This strategic choice reveals the attacker's intent: access to databases, credentials, cloud APIs, and sensitive infrastructure—the typical residents of production servers.


    ## Background: Why Pyrogram Remains Vulnerable


    Pyrogram is described as an "elegant, modern and asynchronous Telegram MTProto API framework in Python," allowing developers to automate bot creation and management. The library was widely adopted before being deprecated—it currently maintains nearly 350,000 monthly downloads on PyPI and has been forked over 1,400 times on GitHub.


    The deprecation created a security gap: while the library remains popular and widely used, it receives no security updates or maintenance. Developers continue using Pyrogram because alternative Python Telegram libraries offer fewer features or less stable APIs. This creates an attractive target for supply chain attackers: a widely-installed library that developers trust but that has no active maintainers to catch malicious additions.


    ## Attribution: A Coordinated Single Actor


    Checkmarx attributes all eight packages to a single threat actor despite their publication from different PyPI accounts. The evidence is compelling:


  • Identical backdoor code across all packages
  • Identical command names and operational patterns
  • Shared OWNERS list (same Telegram IDs across packages)
  • Overlapping infrastructure patterns and registration details

  • This consistency suggests either a single highly disciplined operator or a small team maintaining identical protocols across the campaign.


    ## Implications: The Scope of Potential Compromise


    Developers using any of these packages have likely compromised production infrastructure. The threat extends far beyond the developers themselves:


    Immediate Exposure:


  • Direct access to application source code and dependencies
  • Theft of API keys and authentication tokens for cloud services (AWS, Azure, Google Cloud)
  • Access to database credentials and potentially entire databases
  • Read access to any file the bot application can access

  • Secondary Exposure:


  • Exfiltration of encrypted Telegram sessions and private chats
  • Access to bot user lists and contact information
  • Ability to impersonate the bot for continued communications
  • Installation of additional persistence mechanisms or lateral movement tools

  • Organizations using Telegram bots for business automation—customer support, notifications, or operations—face exposure of all data and systems connected to those bots.


    ## Recommendations for Developers and Organizations


    Immediate Actions (within 24 hours):


    1. Audit dependencies: Check requirements.txt, pipenv files, and setup.py for any reference to the eight malicious package names listed above

    2. Remove packages: Uninstall all versions from production and development environments

    3. Rotate credentials: Assume all API keys, database passwords, and cloud credentials are compromised; rotate them immediately

    4. Revoke tokens: Invalidate all Telegram API tokens and session files; regenerate new ones

    5. Check logs: Search server logs for unexpected /asu or /asi command patterns in Telegram bot activity


    Longer-term Mitigation:


  • Replace Pyrogram with actively maintained alternatives such as python-telegram-bot or aiogram
  • Implement dependency scanning in CI/CD pipelines using tools like Snyk or GitHub Dependabot
  • Require code review for all new dependencies before installation
  • Monitor PyPI for naming variations of critical libraries and set up alerts
  • Implement principle of least privilege for bot service accounts—minimize what credentials and access they require

  • ---


    ## HackWire Analysis


    This campaign reveals a critical vulnerability in how developers trust open-source ecosystems: deprecated popularity is an attacker's advantage. Pyrogram isn't actively maintained precisely because better alternatives exist—yet 350,000 developers still download it monthly. Attackers exploit this gap ruthlessly.


    The sophistication here extends beyond just publishing malicious code. The threat actor deliberately chose package names that mirror the legitimate library (*pyrogram-navy*, *pyrogram-styled*) rather than competing alternatives. They accepted low download counts per package, distributing the risk across eight identities instead of concentrating it on one. Most remarkably, they operated for seven months undetected, achieving 25,000+ compromises before security researchers noticed.


    This pattern—supply chain targeting of deprecated but still-popular libraries—is becoming the dominant attack vector for accessing production infrastructure. We've seen it before with left-pad and event-stream, but this represents an evolution: the attacker maintained operational security through Telegram's own infrastructure, avoiding traditional command servers that might draw detection. The /asu and /asi commands are genius in their simplicity—Python developers would recognize the syntax immediately if they saw logs, yet the backdoor suppresses logging itself.


    What should worry organizations most: many of these compromises are likely still active and undetected. A developer who installed pyrogram-styled in December probably hasn't rotated their database credentials since. A small startup using it for customer support automation may have no logs of what data was accessed. The Telegram bot itself appears to function normally—users won't notice the backdoor unless a developer explicitly inspects command handlers.


    The hardcoded OWNERS list is the attacker's only operational weakness. It means the compromise is personal: specific Telegram accounts have exclusive control, and forensic analysis can identify *who* accessed what, *when*. Every command issued via those Telegram accounts is evidence of the breach.


    If your organization uses *any* Python Telegram bot framework, assume compromise until proven otherwise. Not "might be compromised"—assume it. Rotate everything. Check logs for anomalous file access. This is not a hypothetical risk; it's an active campaign with thousands of confirmed victims.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Supply Chain Security](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)