The article describes a supply chain attack where malicious packages uploaded to the Python Package Index (PyPI) masquerade as legitimate libraries to target developers of Telegram bot servers. When installed, these packages deploy a backdoor that provides attackers with remote control over the compromised system. The summary does not provide specific CVSS scores, affected version ranges, fixed versions, or workarounds.
www.bleepingcomputer.com Performing security verification This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot. Ray ID: a14045fd1adb7304 Performance and Security by Cloudflare Privacy