TeamPCP Targets Telnyx Package in Latest PyPI Software Supply Chain Attack
ID: 0142ccc9-ca60-5c35-add7-b3f62887618b
STIX ID: report--0142ccc9-ca60-5c35-add7-b3f62887618b
Feed Name: Infosecurity Magazine (News)
Threat Score
TeamPCP compromised the official Telnyx Python SDK on PyPI (versions 4.87.1 and 4.87.2), publishing trojanized packages that execute during installation to steal SSH private keys and bash history and exfiltrate them to an attacker-controlled endpoint; researchers from Socket and Endor Labs attribute the issue to a compromised maintainer account and warn this reflects a maturing supply-chain attack methodology with ties to broader ransomware activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
