logo

Hackers Backdoor Telnyx Python SDK on PyPI to Steal Cloud and Dev Credentials

ID: be9869c9-9e64-50cc-ace6-bd2306d57ec5

STIX ID: report--be9869c9-9e64-50cc-ace6-bd2306d57ec5

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-30

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

TeamPCP (linked to TeamTNT) uploaded two trojanized Telnyx Python SDK releases (4.87.1 and 4.87.2) to PyPI; the malicious modification to _client.py executed on import, fetched payloads hidden inside WAV files via steganography, and deployed a cross-platform credential harvester that persisted (e.g., msbuild.exe, sysmon.service), encrypted stolen secrets with AES-256-CBC/RSA-4096, and exfiltrated data to C2 infrastructure (notably 83.142.209.203:8080) using identifiable headers (X-Filename:tpcp.tar.gz); the packages were live for ~4 hours and the report provides IOCs and remediation steps including rotation of all exposed credentials and blocking the attacker subnet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.