TeamPCP Compromises Telnyx Python SDK to Deliver Credential-Stealing Malware
Blog post from Socket
A supply chain attack was identified in the telnyx Python package on PyPI, used widely for real-time communications and telephony integration in applications. Malicious versions 4.87.1 and 4.87.2 contained credential-harvesting malware and were quarantined by PyPI, with users advised to revert to version 4.87.0. The attack, detected by Socket and confirmed by Aikido and Wiz, used a sophisticated three-stage runtime attack chain involving audio steganography for payload delivery, in-memory data harvesting, and encrypted exfiltration, affecting both Windows and Linux/macOS systems differently. The attack leveraged the package's import path to execute its payload, avoiding detection during installation, and targeted environments handling sensitive data like API keys and customer communications. The threat actor, linked to TeamPCP, demonstrated operational sophistication with dual OS-specific attack paths and robust encryption techniques, maintaining a clean dependency footprint and using asymmetric encryption to protect exfiltrated data. The campaign highlights the importance of vigilance in package management and dependency security.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Vector Search | 2 | 2,370 | 415 | 145 | +7% |
| Real-time | 1 | 6,457 | 1,307 | 242 | +28% |
| Secrets Management | 1 | 1,488 | 268 | 99 | +7% |
| Serverless | 1 | 729 | 189 | 89 | -11% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.