logo

TeamPCP strikes again: Backdoored Telnyx PyPI package delivers malware

ID: 9361be1b-15a0-59f0-8129-aa61dd289c1b

STIX ID: report--9361be1b-15a0-59f0-8129-aa61dd289c1b

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-03-27

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Researchers attributed a supply-chain compromise to TeamPCP after malicious Telnyx PyPI releases (4.87.1 and 4.87.2) were published; the backdoored SDK executes on import, retrieves a runtime payload (encoded in WAV audio frames), installs persistence or an infostealer depending on OS, harvests a broad set of secrets (SSH keys, cloud and developer tool credentials, env files, histories, wallets) and can deploy privileged pods to compromise Kubernetes clusters, with stolen data encrypted and exfiltrated. Indicators and cryptographic signatures link the activity to prior TeamPCP compromises and researchers advise treating any detection as a full-environment compromise and rotating all credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.