logo

Telnyx Python SDK Backdoored on PyPI to Steal Cloud Credentials

ID: 2c69a349-08ef-5f5d-ab3d-9bb7c691f69b

STIX ID: report--2c69a349-08ef-5f5d-ab3d-9bb7c691f69b

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

TeamPCP published malicious Telnyx Python SDK releases to PyPI that execute on import to harvest cloud, container, and developer credentials, deploy persistent backdoors on Windows and Kubernetes (using WAV steganography and in‑memory loaders), and exfiltrate data to attacker infrastructure (notably 83.142.209.203:8080 with X-Filename:tpcp.tar.gz). The compromise affected widely used code, bypassed build-integrity controls by using a valid PyPI token, was available for several hours, and is part of a broader multi-ecosystem supply-chain campaign; the report provides IoCs and remediation guidance including credential rotation and blocking known C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.