logo

Telnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach

ID: 56218a62-7c46-5f12-9d40-394da8cef34d

STIX ID: report--56218a62-7c46-5f12-9d40-394da8cef34d

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-03-30

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

This briefing covers several active cybersecurity incidents: TeamPCP pushed malicious Telnyx Python SDK versions to PyPI to distribute a multi-stage infostealer (delivered and decoded from a .wav file), Telnyx recommends treating hosts running versions 4.87.1 or 4.87.2 as compromised and rotating exposed credentials; an alleged RedLine operator was extradited to the US on charges related to infostealer operations; LAPSUS$ published 2.66 GB of purported AstraZeneca data; and Oak Ridge National Laboratory published Photon, an exascale AI vulnerability discovery tool.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.