TeamPCP ha pubblicato su PyPI le versioni malevole 4.87.1 e 4.87.2 del package Telnyx che eseguono un credential-stealer al momento dell'import del SDK. Il malware prende di mira Windows, Linux e macOS e ruba SSH keys, cloud tokens, wallet, vari secret e shell history. La catena usa WAV audio steganography e esfiltra dati via HTTP; PyPI ha messo in quarantena le release e l'ultima versione nota pulita è 4.87.0.
Part of the PlainSec briefing for 2026-03-28
Every edition of this story: TeamPCP Compromette SDK Telnyx su PyPI