Operation Navy Ghost Targets Telegram Bot Developers with Malicious PyPI Packages

Operation Navy Ghost Targets Telegram Bot Developers with Malicious PyPI Packages

First seen 30 Jun 2026, 21:37 UTC Bleepingcomputercheckmarx.com 91% similarity 72.0
Share:

Article Content

Browse articles
ThreatCluster

A malware campaign named Operation Navy Ghost has been targeting Python developers creating Telegram bots by distributing trojanized forks of the popular Pyrogram library. Between November 2025 and June 2026, at least eight malicious packages were published on the Python Package Index (PyPI), each containing a backdoor that allows attackers to gain full control over compromised servers. The backdoor, hidden in a file named secret.py, activates when the bot starts, enabling attackers to execute arbitrary commands and exfiltrate sensitive data. The Pyrogram library, which has nearly 350,000 monthly downloads, remains popular despite being unmaintained. The malicious packages have since been removed from PyPI, but they may still exist in private registries or on developer machines. Organizations are advised to check for these packages and monitor their environments for signs of compromise. The attackers use Telegram for command and control, complicating detection and mitigation efforts.

Key Points: • Operation Navy Ghost targets Telegram bot developers with trojanized Pyrogram forks. • At least eight malicious packages were published on PyPI containing a backdoor for remote control. • Affected organizations should check for these packages and monitor for signs of compromise.

ThreatCluster AI

Timeline

2025-11-01
Malicious packages first published on PyPI
The campaign began with the release of trojanized Pyrogram forks on the Python Package Index, targeting Telegram bot developers.
Checkmarx
2026-06-30
Malicious packages removed from PyPI
Checkmarx reported that the trojanized packages were taken down from PyPI after their discovery, but risks remain for users who downloaded them.
Checkmarx
2026-06-30
Checkmarx issues warning to organizations
Organizations are advised to search for the malicious packages and monitor their systems for signs of compromise due to the ongoing risk.
BleepingComputer

Community

Browse all →