Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
ID: 4deb9bf3-8ea3-5566-8d80-39dea0a67885
STIX ID: report--4deb9bf3-8ea3-5566-8d80-39dea0a67885
Feed Name: Bleeping Computer
TeamPCP published backdoored Telnyx PyPI releases (4.87.1 and 4.87.2) that execute at import and drop a second-stage payload concealed via steganography inside WAV files; Linux/macOS loaders harvest SSH keys, cloud tokens, wallets and Kubernetes secrets while Windows installs a persistent executable. The attack is attributed to TeamPCP, affects a widely used SDK (≈740k downloads/month), and researchers recommend reverting to 4.87.0 and rotating all secrets because systems that imported the malicious versions should be treated as fully compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
