logo

TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files

ID: 20f63c67-31ee-5798-b82b-a6a23db0eb9c

STIX ID: report--20f63c67-31ee-5798-b82b-a6a23db0eb9c

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-27

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

TeamPCP compromised the telnyx PyPI package by publishing malicious versions (4.87.1 and 4.87.2) that embed credential-harvesting payloads inside WAV files using audio steganography; Windows hosts receive a persistent binary dropped to Startup (msbuild.exe) while Linux/macOS perform a fast in-memory harvest and encrypted exfiltration to 83.142.209.203:8080. The incident is part of a wider supply-chain campaign targeting developer and CI tooling, and users are advised to downgrade, rotate secrets, scan environments, and block the C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.