Security researchers have identified three deceptive packages in the npm registry that pose as a legitimate Telegram bot library while secretly containing SSH backdoors and data theft capabilities.