CRITICAL PyPI Malware

Malicious code in pullgetsage (PyPI)

MAL-2026-16366

Published · Modified

Dependency scanning

Check whether pullgetsage is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (93b751049f78b324983511537b6c053a0ed080639dd7c447d87494eabc134ba3)

On import, init.py archives the installer's Telegram Desktop tdata directory (%APPDATA%/Telegram Desktop/tdata) into a zip named 'aiosendletter_logs' and POSTs it to a hardcoded Cloudflare Workers endpoint at https://red-poetry-6b6f.martinmcflywork.workers.dev/. The tdata directory holds Telegram session keys; uploading it enables full account takeover of the installer's Telegram account. The behavior is disguised with misleading identifiers ('aiosendletter_logs', 'aioletter initialized') and empty except-block prints that silently swallow errors, and the stated package purpose ('a library filled with books') is unrelated to Telegram.

Source: kam193 (5a4369fbf36c4c2a54c7555febeaf8fda122d33a7ba9b9d11e77031849f5c7d8)

Package hides code to exfiltrate files. Most releases target unclear files, but some reveal the goal to exfiltrate sensitive Telegram data.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-aiosendletter

Reasons (based on the campaign):

  • files-exfiltration

  • target:telegram

Ready to move

Start Securing

Free, no credit card | First findings in minutes