TeamPCP ha pubblicato versioni dannose 4.87.1 e 4.87.2 del Telnyx Python SDK su PyPI che eseguono un credential harvester all'import. Il malware prende di mira Windows, Linux e macOS, usa WAV audio steganography per consegnare payload specifici e exfiltra i dati verso server controllati dall'attore. PyPI ha messo in quarantena le release compromesse.
Part of the PlainSec briefing for 2026-03-27
Every edition of this story: TeamPCP Compromette SDK Telnyx su PyPI e Ruba Credenziali