logo

Hackers Backdoor Telnyx Python SDK on PyPI to Steal Credentials Across Windows, macOS, and Linux

ID: 5bf81922-c928-5628-ba45-97b8903d21a4

STIX ID: report--5bf81922-c928-5628-ba45-97b8903d21a4

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-04-01

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

TeamPCP backdoored the Telnyx Python SDK on PyPI (versions 4.87.1 and 4.87.2), embedding a credential-stealing payload that executes on import and retrieves an encrypted payload hidden inside WAV files from C&C 83.142.209.203:8080; the attack is cross-platform (Windows/macOS/Linux), used AES-256-CBC and RSA-4096 for exfiltration, and included Windows persistence via a disguised msbuild.exe. PyPI quarantined the malicious releases within ~6.5 hours and users are advised to downgrade to the last clean release (4.87.0), rotate credentials, pin package hashes, and monitor for the listed IOCs (WAV downloads from non-media IPs on port 8080, X-Filename:tpcp.tar.gz header, msbuild.exe in Startup).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.