Blog
Learn about software supply chain security and Endor Labs

Malicious 'Pyronut' Package Backdoors Telegram Bots with Remote Code Execution
The malicious Python package pyronut copies the entire project description and code of the popular pyrogram Telegram framework to pass itself off as the real thing, while silently installing a runtime backdoor that grants the attacker arbitrary Python and shell command execution on every victim's machine.
Book a Demo
Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.












