Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

TeamPCP Strikes Again: Telnyx Compromised Three Days After LiteLLM

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Kiran Raj
Word Count
2,323
Company Posts That Month
35
Language
English
Hacker News Points
-
Post removed?
No
Summary

In March 2026, a sophisticated cyberattack by the threat actor TeamPCP compromised two versions of the telnyx package on PyPI, embedding a multi-stage payload hidden in WAV audio files. This attack, following the earlier litellm compromise, exploited a stolen PyPI API token to insert malicious code in versions 4.87.1 and 4.87.2, while the legitimate SDK remained functional, making the attack stealthy. The payload, delivered through WAV steganography, targeted both Windows and Linux/macOS systems, with platform-specific attack vectors: a persistent binary on Windows and a credential harvester on Linux/macOS. The attack chain involved credential harvesting from various sources, cloud exploitation, Kubernetes lateral movement, and encrypted data exfiltration to a command-and-control server. The malicious versions were quickly identified and quarantined, with the RSA key linking the attack to TeamPCP. The attack underscores the need for enhanced security measures, such as enabling PyPI Trusted Publishers and rotating API tokens, to protect against such vulnerabilities.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 12 1,840 308 106 +33%
Secrets Management 5 1,488 268 99 +7%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.