{"id":155726,"date":"2026-03-29T08:04:15","date_gmt":"2026-03-29T05:04:15","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=155726"},"modified":"2026-03-29T08:04:15","modified_gmt":"2026-03-29T05:04:15","slug":"malware-hidden-in-backdoored-telnyx-pypi-package","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/trending-news\/155726\/malware-hidden-in-backdoored-telnyx-pypi-package\/","title":{"rendered":"Malware hidden in backdoored Telnyx PyPI package"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\" open=\"\"><summary>\u25bc Summary<\/summary><p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Attackers compromised the legitimate Telnyx AI Voice Agent SDK and published malicious versions (4.87.1 and 4.87.2) on the PyPI repository.<br>&#8211; The compromise likely occurred because the attackers previously stole PyPI publishing credentials during an earlier breach of the litellm package.<br>&#8211; The malicious package uses a new delivery method, hiding its payload in a WAV file and fetching the final malware from a command-and-control server at runtime.<br>&#8211; The malware steals a wide range of sensitive data, including cloud credentials and SSH keys, and can deploy persistent implants across entire Kubernetes clusters.<br>&#8211; Security researchers attribute this attack to TeamPCP based on multiple technical indicators, such as a specific encryption scheme, used in their previous supply chain attacks.<br><\/p><\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"color:#f34c3e\" class=\"has-inline-color\">A<\/mark> new <a href=\"https:\/\/digitrendz.blog\/z\/tech-news\/229767\/cisa-issues-new-open-source-software-guidance\/\" class=\"acp-article-link\" data-article-id=\"229767\" title=\"CISA issues new open-source software guidance\" target=\"_blank\" rel=\"noopener noreferrer\">software supply chain<\/a> attack has emerged, with the <strong>Telnyx SDK<\/strong> for AI Voice Agent services being the latest target. Researchers from <a href=\"https:\/\/digitrendz.blog\/z\/entity\/endor-labs\/\" class=\"acp-entity-link\" data-entity-id=\"8317\" data-entity-category=\"Organization\" title=\"Learn more about Endor Labs\" target=\"_blank\" rel=\"noopener noreferrer\">Endor Labs<\/a> have identified malicious versions of this popular Python package uploaded to the official <a href=\"https:\/\/digitrendz.blog\/z\/entity\/pypi\/\" class=\"acp-entity-link\" data-entity-id=\"33314\" data-entity-category=\"Organization\" title=\"Learn more about PyPI\" target=\"_blank\" rel=\"noopener noreferrer\">PyPI<\/a> repository. The threat actors, identified as <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/teampcp\/\" class=\"acp-entity-link\" data-entity-id=\"229794\" data-entity-category=\"Organization\" title=\"Learn more about TeamPCP\" target=\"_blank\" rel=\"noopener noreferrer\">TeamPCP<\/a><\/strong>, backdoored the legitimate code and published two compromised versions, 4.87.1 and 4.87.2, in quick succession on March 27, 2026. The first version contained a typo that rendered the malicious code non-functional, forcing the attackers to issue a corrected release shortly after.<\/p>\n\n<p class=\"wp-block-paragraph\">The attack vector likely stems from a <a href=\"https:\/\/digitrendz.blog\/z\/topic\/previous-compromises\/\" class=\"acp-topic-link\" data-topic-id=\"191677\" title=\"Explore: previous compromises\" target=\"_blank\" rel=\"noopener noreferrer\">previous compromise<\/a>. According to Endor Labs researcher <a href=\"https:\/\/digitrendz.blog\/z\/entity\/kiran-raj\/\" class=\"acp-entity-link\" data-entity-id=\"233025\" data-entity-category=\"Person\" title=\"Learn more about Kiran Raj\" target=\"_blank\" rel=\"noopener noreferrer\">Kiran Raj<\/a>, the group\u2019s earlier breach of the <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/litellm\/\" class=\"acp-entity-link\" data-entity-id=\"105900\" data-entity-category=\"product\" title=\"Learn more about LiteLLM\" target=\"_blank\" rel=\"noopener noreferrer\">LiteLLM<\/a> project<\/strong> provided them with a trove of stolen credentials. Their malware harvested environment variables and configuration files from any system that imported LiteLLm. If a developer or <a href=\"https:\/\/digitrendz.blog\/z\/entity\/ci-pipeline\/\" class=\"acp-entity-link\" data-entity-id=\"233026\" data-entity-category=\"Technology\" title=\"Learn more about CI pipeline\" target=\"_blank\" rel=\"noopener noreferrer\">CI pipeline<\/a> with LiteLLm installed also had access to the <a href=\"https:\/\/digitrendz.blog\/z\/entity\/telnyx\/\" class=\"acp-entity-link\" data-entity-id=\"233022\" data-entity-category=\"product\" title=\"Learn more about telnyx\" target=\"_blank\" rel=\"noopener noreferrer\">Telnyx<\/a> PyPI publishing token, that credential was likely captured. The three-day gap between the LiteLLm and Telnyx incidents aligns with the time needed to sift through stolen data and select the next high-value target. The telnyx project on PyPI has now been quarantined.<\/p>\n\n<p class=\"wp-block-paragraph\">This latest incident reveals an evolution in <strong>TeamPCP&#8217;s malware delivery<\/strong> tactics. Unlike previous attacks, the malicious payload was embedded within the audio frame data of a legitimate <a href=\"https:\/\/digitrendz.blog\/z\/entity\/wav\/\" class=\"acp-entity-link\" data-entity-id=\"233027\" data-entity-category=\"Technology\" title=\"Learn more about WAV\" target=\"_blank\" rel=\"noopener noreferrer\">WAV<\/a> file. The <a href=\"https:\/\/digitrendz.blog\/z\/tech-news\/196511\/depthfirst-blocks-malicious-dependencies-before-installation\/\" class=\"acp-article-link\" data-article-id=\"196511\" title=\"Depthfirst blocks malicious dependencies before installation\" target=\"_blank\" rel=\"noopener noreferrer\">malicious packages<\/a> were also smaller, as the real payload is fetched at runtime from a command-and-control server using a raw IP address. When the compromised Telnyx package is imported, it executes immediately. On <a href=\"https:\/\/digitrendz.blog\/z\/entity\/windows\/\" class=\"acp-entity-link\" data-entity-id=\"284\" data-entity-category=\"Technology\" title=\"Learn more about Windows\" target=\"_blank\" rel=\"noopener noreferrer\">Windows<\/a> systems, it retrieves and installs a persistent executable. On <a href=\"https:\/\/digitrendz.blog\/z\/entity\/linux\/\" class=\"acp-entity-link\" data-entity-id=\"4602\" data-entity-category=\"Technology\" title=\"Learn more about Linux\" target=\"_blank\" rel=\"noopener noreferrer\">Linux<\/a> and <a href=\"https:\/\/digitrendz.blog\/z\/entity\/macos\/\" class=\"acp-entity-link\" data-entity-id=\"7265\" data-entity-category=\"Technology\" title=\"Learn more about macOS\" target=\"_blank\" rel=\"noopener noreferrer\">macOS<\/a>, it deploys a sophisticated <strong>information stealer<\/strong>.<\/p>\n\n<p class=\"wp-block-paragraph\">This stealer is designed to exfiltrate a vast array of sensitive data, including SSH keys, cloud credentials, and authentication details from tools like Docker, npm, and Git. It also targets database credentials, environment configuration files, shell histories, and cryptocurrency wallet data. The malware exhibits particularly aggressive behavior in <a href=\"https:\/\/digitrendz.blog\/z\/entity\/kubernetes\/\" class=\"acp-entity-link\" data-entity-id=\"12306\" data-entity-category=\"Technology\" title=\"Learn more about Kubernetes\" target=\"_blank\" rel=\"noopener noreferrer\">Kubernetes<\/a> environments. If it discovers a service account token, it attempts to compromise the entire cluster by deploying a privileged pod to every node, mounting the host filesystem to install a persistence implant directly.<\/p>\n\n<p class=\"wp-block-paragraph\">Analysts have confirmed the attack bears the hallmarks of <strong>TeamPCP<\/strong>, the same group behind the recent Trivy, LiteLLm, and Checkmarx compromises. The attribution is based on multiple technical indicators, including the use of a specific RSA-4096 public key and an identical encryption scheme for data exfiltration seen in the LiteLLm attack. Researchers have published detailed indicators of compromise and advise that any match should be treated as a full-environment breach, necessitating the rotation of all credentials. Further analysis and mitigation guidance are available from SafeDep and Aikido Security researchers.<\/p>\n\n<em>(Source: <a href='https:\/\/helpnetsecurity.com\/2026\/03\/27\/teampcp-telnyx-supply-chain-compromise\/' target='_blank'>Help Net Security<\/a>)<\/em>","protected":false},"excerpt":{"rendered":"<p>A malicious version of the Telnyx SDK Python package was uploaded to PyPI on March 27, 2026, by the threat actor TeamPCP, who backdoored the legitimate code. The attack originated from stolen credentials obtained in a prior breach of the LiteLLM project, which were used to compromise the Telnyx P&#8230;<\/p>\n","protected":false},"author":1,"featured_media":155725,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[3247,3297,3327,3254,497],"tags":[78508,187261,6850,187259,187260],"entities":[86084,76760,187268,5009,5379,5182,49966,187263,187269,7241,3477,70712,4652,187266,64003,24009,187264,33215,184066,187262,187265,108643,125154,187267,955],"class_list":["post-155726","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-artificial-intelligence","category-cybersecurity","category-newswire","category-technology","category-trending-news","tag-information-stealer","tag-pypi-malware","tag-software-supply-chain","tag-teampcp","tag-telnyx-sdk","entity-c2","entity-checkmarx","entity-ci-pipeline","entity-docker","entity-endor-labs","entity-git","entity-github-actions","entity-kiran-raj","entity-kube-system","entity-kubernetes","entity-linux","entity-litellm","entity-macos","entity-models-litellm-cloud","entity-npm-2","entity-pypi","entity-python-package-index","entity-ssh","entity-teampcp","entity-telnyx","entity-telnyx-ai-voice-agent","entity-trivy","entity-vault","entity-wav","entity-windows"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/155726","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=155726"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/155726\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/155725"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=155726"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=155726"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=155726"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=155726"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}