-= Per source details. Do not edit below this line.=-
The package implements a full remote-administration toolkit controlled through a Telegram bot. It polls the Telegram Bot API at https://api.telegram.org/bot<token>/... and dispatches inbound messages to handlers that execute arbitrary system commands via subprocess.run (documented in the README as a run command that executes any system command), create OS users, change sudo/RDP privileges, and upload/download arbitrary files on the host. A BotFinder routine walks /, /home, /root, /etc, /var/www, /opt, /tmp, /usr/local, and Windows drives, reading.py/.json/.conf/.cfg/.env/.ini files and regex-extracting Telegram bot tokens (pattern [0-9]+:[A-Za-z0-9_-]+) along with token/api_token/webhook context. Additional bot commands (getpasswords, getsshkeys, rdp, rdpall, findbot, getallbots) return the harvested SSH keys, saved credentials, and other operators' bot tokens back over the Telegram channel. Any host on which this package runs is fully controllable by whoever holds the bot token, and installer-side secrets are exfiltrated to that operator. Package metadata lists a placeholder author (Umar <umar@example.com>) and a non-existent GitHub slug, consistent with anonymous publication of a RAT under a data-analytics-sounding name.
9.0.19.0.4Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H