logo

TeamPCP Targets Telnyx Package in Latest PyPI Software Supply Chain Attack

ID: 0142ccc9-ca60-5c35-add7-b3f62887618b

STIX ID: report--0142ccc9-ca60-5c35-add7-b3f62887618b

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

...
...

TeamPCP compromised the official Telnyx Python SDK on PyPI (versions 4.87.1 and 4.87.2), publishing trojanized packages that execute during installation to steal SSH private keys and bash history and exfiltrate them to an attacker-controlled endpoint; researchers from Socket and Endor Labs attribute the issue to a compromised maintainer account and warn this reflects a maturing supply-chain attack methodology with ties to broader ransomware activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.