logo

PyPI Telnyx Python SDK Backdoored to Steal Credentials on Windows, macOS, and Linux

ID: abf58596-2359-55b2-b4fc-7907973e64e3

STIX ID: report--abf58596-2359-55b2-b4fc-7907973e64e3

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A malicious update to the Telnyx Python SDK (versions 4.87.1 and 4.87.2) was published to PyPI and included a module-level backdoor that uses WAV steganography to fetch and reconstruct a cross-platform credential stealer; TeamPCP is attributed based on shared RSA‑4096 keys, the tpcp.tar.gz exfiltration pipeline, and other toolchain overlaps. The malware executes on import, supports Windows (dropping msbuild.exe in Startup) and Unix-like systems, exfiltrates harvested secrets via HTTP POSTs to 83.142.209.203:8080 with an X-Filename:tpcp.tar.gz header, and remained publicly available for roughly 6.5 hours—users should revert to Telnyx 4.87.0, rotate credentials, and hunt for the described IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.