TeamPCP Uses Fake Ringtone File in Tainted Telnyx SDK to Steal Credentials
ID: 38f74634-8ec2-5fbf-8d87-332f672c7ac7
STIX ID: report--38f74634-8ec2-5fbf-8d87-332f672c7ac7
Feed Name: HackRead
Researchers attribute a supply-chain compromise of the Telnyx Python SDK to the TeamPCP group: two malicious package versions (4.87.1 and 4.87.2) contained code in _client.py that downloaded a scrambled `ringtone.wav` which executed to search for SSH keys, cloud credentials, and cryptocurrency wallets. The tainted packages were available on 27 March 2026 and affected users who ran `pip install telnyx` during that window; Telnyx confirmed their infrastructure was not breached and advised reverting to 4.87.0 and rotating secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
