Hackers Backdoor Telnyx Python SDK on PyPI to Steal Cloud and Dev Credentials
ID: be9869c9-9e64-50cc-ace6-bd2306d57ec5
STIX ID: report--be9869c9-9e64-50cc-ace6-bd2306d57ec5
Feed Name: cybersecurityNews.com
TeamPCP (linked to TeamTNT) uploaded two trojanized Telnyx Python SDK releases (4.87.1 and 4.87.2) to PyPI; the malicious modification to _client.py executed on import, fetched payloads hidden inside WAV files via steganography, and deployed a cross-platform credential harvester that persisted (e.g., msbuild.exe, sysmon.service), encrypted stolen secrets with AES-256-CBC/RSA-4096, and exfiltrated data to C2 infrastructure (notably 83.142.209.203:8080) using identifiable headers (X-Filename:tpcp.tar.gz); the packages were live for ~4 hours and the report provides IOCs and remediation steps including rotation of all exposed credentials and blocking the attacker subnet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
