216.73.216.6

TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM

· Published 30/03/2026 18:06 · Modified 30/03/2026 21:46

Export JSON

Essential information

Published
30/03/2026 18:06
Modified
30/03/2026 21:46
Tags
2026-03-30 base64 encoding credential-theft multi-platform persistence pypi steganography supply chain attack wav files
Related entities
5 observables, 1 intrusion sets (apt), 10 techniques (mitre)

Description

TeamPCP launched a sophisticated attack on the Telnyx Python SDK, publishing malicious versions 4.87.1 and 4.87.2 to . The attack represents an evolution from their previous LiteLLM campaign, incorporating WAV-based , split-file code injection, and expanded platform support. The payload, activated on import, uses stealthy techniques to download and execute credential-stealing malware across Linux, macOS, and Windows systems. Key changes include the use of audio to hide malicious code, improved evasion through split-file injection, and the addition of Windows support with Startup folder . The attackers shifted from HTTPS to plaintext HTTP infrastructure, potentially exposing their activities to network monitoring. Organizations are advised to downgrade to the last clean version and treat affected systems as compromised.

External references