{"id":1012,"date":"2026-07-01T13:52:33","date_gmt":"2026-07-01T08:22:33","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1012"},"modified":"2026-08-19T13:56:26","modified_gmt":"2026-08-19T08:26:26","slug":"operation-navy-ghost-pypi-telegram-bot-backdoor","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/","title":{"rendered":"Operation Navy Ghost: Malicious PyPI Packages Backdoor Telegram Bot Servers"},"content":{"rendered":"<h2>Introduction<\/h2>\n<p>A newly disclosed software supply chain campaign has highlighted how a seemingly legitimate Python dependency can provide attackers with remote control over servers running Telegram bots. Dubbed Operation Navy Ghost, the campaign involved malicious PyPI packages masquerading as forks of the popular Pyrogram framework.<\/p>\n<p>Once installed, the modified packages reportedly registered hidden Telegram command handlers capable of executing attacker-supplied Python code or shell commands on infected systems.<\/p>\n<p>Rather than targeting Telegram itself, the attackers abused the trust developers place in public package repositories. The incident shows how third-party dependencies can become an attack vector capable of reaching production infrastructure through routine software development workflows.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" target=\"_blank\">\r\n    \t\tSecure Your Endpoints with Hexnode<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How the Operation Navy Ghost Attack Worked<\/h2>\n<p>The campaign, reportedly active since November 2025, involved at least eight malicious packages uploaded to PyPI as modified versions of the legitimate Pyrogram framework.<\/p>\n<p>The trojanized packages preserved Pyrogram&#8217;s expected functionality while introducing additional malicious code inside a helper module named secret.py.<\/p>\n<p>When an affected Telegram bot started, the malware reportedly:<\/p>\n<ul>\n<li>Registered hidden Telegram command handlers<\/li>\n<li>Accepted commands from attacker-controlled Telegram accounts<\/li>\n<li>Executed arbitrary Python code<\/li>\n<li>Executed shell commands on the host<\/li>\n<li>Returned command output through Telegram<\/li>\n<li>Read files accessible to the compromised application<\/li>\n<li>Suppressed errors and logging to reduce visibility<\/li>\n<\/ul>\n<p>Because the malware retained the expected behavior of the legitimate library, developers may not have noticed any operational issues after installation. This combination of normal application functionality and concealed backdoor logic is characteristic of modern software supply-chain attacks, where malicious code is designed to blend into trusted development workflows.<\/p>\n<h2>What Is Confirmed and What Remains Unclear<\/h2>\n<p>The published analysis confirms that the affected packages contained embedded backdoor functionality capable of providing remote command execution through Telegram-based command handlers.<\/p>\n<p>It also confirms that the campaign specifically targeted developers using Pyrogram-based Telegram applications.<\/p>\n<p>However, several important questions remain unanswered publicly:<\/p>\n<ul>\n<li>The campaign has not been attributed to a known named threat group.<\/li>\n<li>No victim organizations have been identified.<\/li>\n<li>The number of compromised environments has not been disclosed.<\/li>\n<li>Public reporting has not confirmed credential theft, data theft from named victim organizations, or follow-on intrusions resulting from the campaign, although the malware reportedly included data exfiltration capabilities.<\/li>\n<\/ul>\n<p>Although the malware was capable of executing commands and accessing files available to the compromised application, organizations should avoid assuming every installation resulted in a successful compromise without further investigation.<\/p>\n<h2>Why Operation Navy Ghost Matters for Enterprises<\/h2>\n<p>Although the campaign specifically targeted Python developers building Telegram bots, the broader implications extend well beyond developer workstations.<\/p>\n<p>Production bot applications often operate with access to valuable enterprise resources, including:<\/p>\n<ul>\n<li>Environment variables<\/li>\n<li><a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-api-key\/\">API keys<\/a><\/li>\n<li>Cloud credentials<\/li>\n<li>Internal databases<\/li>\n<li>Customer messaging data<\/li>\n<li>Business automation workflows<\/li>\n<\/ul>\n<p>If a compromised application runs with access to these resources, attackers may be able to leverage the application&#8217;s existing permissions to expand their access. The privileges granted to the affected service determine the potential impact, and public reporting has not universally confirmed that impact across this campaign.<\/p>\n<p>The incident demonstrates why organizations should treat dependency security as a core component of enterprise security. Malicious packages that preserve expected functionality can evade casual inspection, allowing compromised software to move from development into production unless organizations maintain strong software governance and endpoint visibility.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/All-Images-6_11zon-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Ensure Software Supply Chain Security with Hexnode UEM<\/h4><p>Learn how Hexnode helps strengthen software supply chain security with runtime visibility, and policy enforcement.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/ensure-software-supply-chain-security-with-hexnode-uem\/\" aria-label=\"Ensure Software Supply Chain Security with Hexnode UEM\"><\/a><\/div><\/div><\/div><\/p>\n<h2>Recommended Mitigations<\/h2>\n<p>Organizations that suspect they may have installed one of the affected packages should prioritize containment and validation.<\/p>\n<p>Recommended actions include:<\/p>\n<ul>\n<li>Remove the malicious packages from development and production environments.<\/li>\n<li>Revoke and regenerate Telegram bot tokens.<\/li>\n<li>Rotate credentials that may have been accessible from affected systems.<\/li>\n<li>Review endpoint telemetry and application logs for unexpected Python or shell activity.<\/li>\n<li>Validate third-party software dependencies before deployment.<\/li>\n<li>Maintain an inventory of packages used across production workloads.<\/li>\n<li>Review developer workstations and internal package repositories for cached copies of the affected packages.<\/li>\n<\/ul>\n<p>These measures can help reduce the likelihood that compromised dependencies remain active after package removal and support a more effective incident response.<\/p>\n<h2>How Hexnode Can Help<\/h2>\n<p>Responding to software supply-chain incidents requires visibility into affected endpoints, the ability to investigate suspicious activity, and consistent enforcement of endpoint policies.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can help organizations strengthen developer endpoint hygiene by:<\/p>\n<ul>\n<li>Enforcing operating system update policies<\/li>\n<li>Managing approved applications<\/li>\n<li>Supporting managed application deployment<\/li>\n<li>Applying device compliance policies<\/li>\n<li>Restricting unauthorized software where appropriate<\/li>\n<\/ul>\n<p>If suspicious activity is identified on managed endpoints, <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> can support endpoint investigation and response by helping security teams:<\/p>\n<ul>\n<li>Review historical endpoint activity<\/li>\n<li>Investigate suspicious endpoint behavior using endpoint telemetry<\/li>\n<li>Isolate affected devices from the network<\/li>\n<li>Terminate suspicious processes as part of incident response<\/li>\n<\/ul>\n<p><section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck.webp?format=webp\" class=\"resource-box__image\" alt=\"Thumbnail-For-XDR-Intro-Deck\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck.webp?format=webp 1796w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-300x168.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1024x575.webp?format=webp 1024w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-768x431.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1536x862.webp?format=webp 1536w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-178x100.webp?format=webp 178w\" sizes=\"auto, (max-width: 1796px) 100vw, 1796px\" title=\"Thumbnail-For-XDR-Intro-Deck\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Introduction to Hexnode XDR\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how Hexnode XDR helps security teams investigate suspicious endpoint activity and respond to threats more effectively.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/introduction-to-hexnode-xdr\/'>\n                            Download the Presentation\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><br \/>\nOrganizations using <a href=\"https:\/\/www.hexnode.com\/idp\/\">Hexnode IdP<\/a> can further strengthen access controls through multi-factor authentication (MFA), role-based access control (RBAC), Microsoft Entra ID integration, and device compliance checks.<\/p>\n<p>While these capabilities do not prevent software supply-chain attacks, they can improve endpoint visibility, support investigations, and help organizations respond to suspicious activity across managed environments.<\/p>\n<h2>Key Takeaways from Operation Navy Ghost<\/h2>\n<p>Operation Navy Ghost highlights how <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/malicious-pypi-packages-give-hackers-control-of-telegram-bot-servers\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=5g_security\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">software supply-chain attacks can abuse developer dependencies instead of directly targeting enterprise infrastructure<\/a>.<\/p>\n<p>Organizations building applications on open-source ecosystems should make dependency governance a core security control. They should pair it with endpoint visibility, credential hygiene, and incident response.<\/p>\n<p>Organizations should verify third-party packages before deployment. They should also maintain endpoint visibility and respond quickly to suspicious activity. These practices can help reduce the operational impact of compromised dependencies.<\/p>\n<p>While investigators continue to analyze this campaign, organizations should continuously validate software trust throughout the development lifecycle instead of assuming it at installation.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5> Secure Developer Endpoints with Confidence<\/h5><p>Protect development environments with device compliance, and endpoint investigation capabilities designed to help reduce risk across your organization.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Try Hexnode Now<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Introduction A newly disclosed software supply chain campaign has highlighted how a seemingly legitimate Python&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1014,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,15],"class_list":["post-1012","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-malware","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Operation Navy Ghost: PyPI Backdoor Targets Telegram Bots<\/title>\n<meta name=\"description\" content=\"See how Operation Navy Ghost used malicious packages to backdoor Telegram bot servers, highlighting supply chain attack risks for enterprises.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Operation Navy Ghost: PyPI Backdoor Targets Telegram Bots\" \/>\n<meta property=\"og:description\" content=\"See how Operation Navy Ghost used malicious packages to backdoor Telegram bot servers, highlighting supply chain attack risks for enterprises.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-01T08:22:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T08:26:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Operation-Navy-Ghost-Malicious-PyPI-Packages-Backdoor-Telegram-Bot-Server.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"Operation Navy Ghost: Malicious PyPI Packages Backdoor Telegram Bot Servers\",\"datePublished\":\"2026-07-01T08:22:33+00:00\",\"dateModified\":\"2026-08-19T08:26:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/\"},\"wordCount\":937,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Operation-Navy-Ghost-Malicious-PyPI-Packages-Backdoor-Telegram-Bot-Server.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/\",\"name\":\"Operation Navy Ghost: PyPI Backdoor Targets Telegram Bots\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Operation-Navy-Ghost-Malicious-PyPI-Packages-Backdoor-Telegram-Bot-Server.jpeg?format=webp\",\"datePublished\":\"2026-07-01T08:22:33+00:00\",\"dateModified\":\"2026-08-19T08:26:26+00:00\",\"description\":\"See how Operation Navy Ghost used malicious packages to backdoor Telegram bot servers, highlighting supply chain attack risks for enterprises.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Operation-Navy-Ghost-Malicious-PyPI-Packages-Backdoor-Telegram-Bot-Server.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Operation-Navy-Ghost-Malicious-PyPI-Packages-Backdoor-Telegram-Bot-Server.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"Operation Navy Ghost Malicious PyPI Packages Backdoor Telegram Bot Server\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-navy-ghost-pypi-telegram-bot-backdoor\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Operation Navy Ghost: Malicious PyPI Packages Backdoor Telegram Bot Servers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Operation Navy Ghost: PyPI Backdoor Targets Telegram Bots","description":"See how Operation Navy Ghost used malicious packages to backdoor Telegram bot servers, highlighting supply chain attack risks for enterprises.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/","og_locale":"en_US","og_type":"article","og_title":"Operation Navy Ghost: PyPI Backdoor Targets Telegram Bots","og_description":"See how Operation Navy Ghost used malicious packages to backdoor Telegram bot servers, highlighting supply chain attack risks for enterprises.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-01T08:22:33+00:00","article_modified_time":"2026-08-19T08:26:26+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Operation-Navy-Ghost-Malicious-PyPI-Packages-Backdoor-Telegram-Bot-Server.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"Operation Navy Ghost: Malicious PyPI Packages Backdoor Telegram Bot Servers","datePublished":"2026-07-01T08:22:33+00:00","dateModified":"2026-08-19T08:26:26+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/"},"wordCount":937,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Operation-Navy-Ghost-Malicious-PyPI-Packages-Backdoor-Telegram-Bot-Server.jpeg?format=webp","articleSection":["Identity Abuse","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/","url":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/","name":"Operation Navy Ghost: PyPI Backdoor Targets Telegram Bots","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Operation-Navy-Ghost-Malicious-PyPI-Packages-Backdoor-Telegram-Bot-Server.jpeg?format=webp","datePublished":"2026-07-01T08:22:33+00:00","dateModified":"2026-08-19T08:26:26+00:00","description":"See how Operation Navy Ghost used malicious packages to backdoor Telegram bot servers, highlighting supply chain attack risks for enterprises.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Operation-Navy-Ghost-Malicious-PyPI-Packages-Backdoor-Telegram-Bot-Server.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Operation-Navy-Ghost-Malicious-PyPI-Packages-Backdoor-Telegram-Bot-Server.jpeg?format=webp","width":1340,"height":754,"caption":"Operation Navy Ghost Malicious PyPI Packages Backdoor Telegram Bot Server"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-navy-ghost-pypi-telegram-bot-backdoor\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Operation Navy Ghost: Malicious PyPI Packages Backdoor Telegram Bot Servers"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1012","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1012"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1012\/revisions"}],"predecessor-version":[{"id":1016,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1012\/revisions\/1016"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1014"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1012"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1012"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}