Python Packages Peek in Telegram, Set Up Windows RDP Access

This Week in Malware - Python Packages Peek Into Your Telegram, Set Up Windows RDP Access

July 08, 2022
By Ax Sharma

3 minute read time

This week in malware, we discovered and analyzed multiple malicious PyPI packages that either set up new Remote Desktop user accounts on your Windows computer or steal encrypted Telegram data files from your Telegram Desktop client.

PyPI Packages Steal Your Telegram Desktop Files, Set Up Windows RDP Access

The primary packages of interest conducting malicious activities are:

These packages were discovered by Sonatype's automated malware detection system, offered as a part of the Sonatype Platform products, including Sonatype Firewall. On a further review, we deemed these packages malicious and reported them to PyPI.

Check out the dedicated blog post to learn more.

Dependency Confusion Packages

The week's dependency confusion findings, across npm and PyPI, include the following packages.

Turn on Sonatype Firewall for Automatic Protection

This discovery follows our last week's report of malicious Python cryptominers and over 345 dependency confusion packages that were timely discovered and reported by Sonatype.

As a DevSecOps organization, we remain committed to identifying and halting attacks against open source developers and the wider software supply chain, like the ones discussed above.

Users of Sonatype Firewall can rest easy knowing that such malicious packages would automatically be blocked from reaching their development builds.


Sonatype Firewall instances will automatically quarantine any suspicious components detected by our automated malware detection systems while a manual review by a researcher is in the works, thereby keeping your software supply chain protected from the start.

Sonatype's world-class security research data, combined with our automated malware detection technology safeguards your developers, customers, and software supply chain from infections.

Written by Ax Sharma

Ax is a security researcher, malware analyst and journalist with a penchant for open source software. His works and expert analyses have frequently been featured by leading media outlets including the BBC. Ax's expertise lies in security vulnerability research, reverse engineering, and cybercrime investigations. He has a passion for educating a wide range of audiences through writing and vlogs.