PyPI Telnyx Python SDK Backdoored to Steal Credentials on Windows, macOS, and Linux
ID: abf58596-2359-55b2-b4fc-7907973e64e3
STIX ID: report--abf58596-2359-55b2-b4fc-7907973e64e3
Feed Name: GBHackers
A malicious update to the Telnyx Python SDK (versions 4.87.1 and 4.87.2) was published to PyPI and included a module-level backdoor that uses WAV steganography to fetch and reconstruct a cross-platform credential stealer; TeamPCP is attributed based on shared RSA‑4096 keys, the tpcp.tar.gz exfiltration pipeline, and other toolchain overlaps. The malware executes on import, supports Windows (dropping msbuild.exe in Startup) and Unix-like systems, exfiltrates harvested secrets via HTTP POSTs to 83.142.209.203:8080 with an X-Filename:tpcp.tar.gz header, and remained publicly available for roughly 6.5 hours—users should revert to Telnyx 4.87.0, rotate credentials, and hunt for the described IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
