A typosquatted Python package on PyPI impersonating a popular parser library deployed a Telegram backdoor to steal credentials and API…