216.73.217.22

Telnyx Python SDK Compromised to Deliver Credential-Stealing Malware

· Published 28/03/2026 07:39 · Modified 30/03/2026 10:12

Export JSON

Essential information

Published
28/03/2026 07:39
Modified
30/03/2026 10:12
Tags
2026-03-28 credential harvesting fileless execution hybrid encryption pypi steganography supply chain attack telnyx
Related entities
3 observables, 1 intrusion sets (apt), 13 techniques (mitre)

Description

A affecting the Python package on has been identified. Malicious versions 4.87.1 and 4.87.2 contained embedded credential-harvesting malware. The attack employs a three-stage runtime chain on Linux/macOS using audio for delivery, in-memory execution of a data harvester, and encrypted exfiltration. On Windows, it drops a persistent binary in the Startup folder. The malware uses sophisticated techniques including , , and anti-forensics measures. The threat actor, TeamPCP, demonstrates high operational security and cryptographic awareness. Developers are advised to audit environments, rotate credentials, and check for indicators of compromise.

External references