Logo
pypi

shortneer@0.1.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2026-17422

Ecosystem

pypi

Summary

The package ships a macOS arm64 Rust-compiled Python extension (_core.abi3.so) fronted by a thin wrapper lb.py. The only exposed Python function, shortname(), invokes two gibberish-named native entrypoints (_core.dphjx0rdhx0 and _core.ioluli0x0xthf) and swallows all exceptions with a silent print(''). The native binary embeds the hardcoded path 'Library/Application Support/Telegram Desktop/tdata' (the installer's Telegram Desktop session store on macOS), the archive name 'fghj.zip', and the destination 'https://api.telegram.org', alongside zip, AES, ChaCha20 and reqwest/rustls/hyper HTTP client code. This matches packaging the installer's live Telegram Desktop session directory and uploading it to a Telegram bot controlled by the author, which grants full takeover of the installer's Telegram account. The random-looking native export names and the blanket exception suppression serve to hide the behavior from casual inspection; the package's self-description as an OSINT utility does not match its actual data flow, which targets the installer's own messaging session store rather than any user-supplied target.

Source: amazon-inspector (4960c121d2fbf6337d33df0c6a304f4f3e968d18c64614c323ac5f8389020bab)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.