logo

TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM

ID: 573e6366-7cb8-5254-8827-51f5de13ac48

STIX ID: report--573e6366-7cb8-5254-8827-51f5de13ac48

Feed Name: TrendAI Security Blog

Threat Score
85/100

Date Published: 2026-03-27

Date Updated: 2026-08-12

...
...

TeamPCP published two malicious Telnyx Python SDK releases to PyPI (v4.87.1 and v4.87.2) that execute on import and use split-file injection and WAV audio steganography to deliver a credential-stealing payload; the campaign reuses cryptographic/exfiltration tooling from a prior LiteLLM compromise and expands targeting to Windows with a persistence mechanism (msbuild.exe in user Startup). The packages were quarantined by PyPI after ~6.5 hours of exposure; the report outlines technical analysis, IOCs, and defensive recommendations such as downgrading to 4.87.0, hashing/pinning dependencies, and monitoring for WAV downloads from suspicious IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.