logo

TeamPCP Uses Fake Ringtone File in Tainted Telnyx SDK to Steal Credentials

ID: 38f74634-8ec2-5fbf-8d87-332f672c7ac7

STIX ID: report--38f74634-8ec2-5fbf-8d87-332f672c7ac7

Feed Name: HackRead

Threat Score
85/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Researchers attribute a supply-chain compromise of the Telnyx Python SDK to the TeamPCP group: two malicious package versions (4.87.1 and 4.87.2) contained code in _client.py that downloaded a scrambled `ringtone.wav` which executed to search for SSH keys, cloud credentials, and cryptocurrency wallets. The tainted packages were available on 27 March 2026 and affected users who ran `pip install telnyx` during that window; Telnyx confirmed their infrastructure was not breached and advised reverting to 4.87.0 and rotating secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.