Minacce e avversari · Supply chain
TeamPCP Compromette SDK Telnyx su PyPI TeamPCP ha pubblicato su PyPI le versioni malevole 4.87.1 e 4.87.2 del package Telnyx che eseguono un credential-stealer al momento dell'import del SDK. Il malware prende di mira Windows, Linux e macOS e ruba SSH keys, cloud tokens, wallet, vari secret e shell history. La catena usa WAV audio steganography e esfiltra dati via HTTP; PyPI ha messo in quarantena le release e l'ultima versione nota pulita è 4.87.0 .
12 fonti · 3 apr
Cronologia Fonti 3 apr Dark Reading
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
As organizations disclose breaches tied to TeamPCP's supply chain attacks, ShinyHunters and Lapsus$ are creating a murky situation for enterprises.
originale 1 apr Unit 42
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure
TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group.
originale 30 mar Help Net Security
TeamPCP’s attack spree slows, but threat escalates with ransomware pivot - Help Net Security
TeamPCP has shifted from supply chain expansion to monetization of existing credential harvests by partnering with ransomware attackers.
originale Part of the PlainSec briefing for 2026-03-28
Every edition of this story: TeamPCP Compromette SDK Telnyx su PyPI
Altro da oggi
Minacce e avversari · Supply chain
TeamPCP Compromette SDK Telnyx su PyPI TeamPCP ha pubblicato su PyPI le versioni malevole 4.87.1 e 4.87.2 del package Telnyx che eseguono un credential-stealer al momento dell'import del SDK. Il malware prende di mira Windows, Linux e macOS e ruba SSH keys, cloud tokens, wallet, vari secret e shell history. La catena usa WAV audio steganography e esfiltra dati via HTTP; PyPI ha messo in quarantena le release e l'ultima versione nota pulita è 4.87.0 .
12 fonti · 3 apr
Cronologia Fonti 3 apr Dark Reading
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
As organizations disclose breaches tied to TeamPCP's supply chain attacks, ShinyHunters and Lapsus$ are creating a murky situation for enterprises.
originale 1 apr Unit 42
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure
TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group.
originale 30 mar Help Net Security
TeamPCP’s attack spree slows, but threat escalates with ransomware pivot - Help Net Security
TeamPCP has shifted from supply chain expansion to monetization of existing credential harvests by partnering with ransomware attackers.
originale Part of the PlainSec briefing for 2026-03-28
Every edition of this story: TeamPCP Compromette SDK Telnyx su PyPI
Altro da oggi