Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Telnyx Versions on PyPI: Audio Steganography Attack

Malicious Telnyx Versions on PyPI: Audio Steganography Attack

Posted on March 27, 2026 By CWS

In a sophisticated cyberattack, TeamPCP has targeted the Telnyx package available on the Python Package Index (PyPI), introducing two compromised versions aimed at stealing confidential information. This breach follows their previous attack on popular tools like Trivy and KICS. The malicious versions, 4.87.1 and 4.87.2, surfaced on March 27, 2026, employing a unique method of embedding credential-stealing malware within a .WAV file. Users are urged to revert to version 4.87.0 promptly as the compromised versions are now quarantined.

Details of the Telnyx Compromise

Reports from multiple cybersecurity firms including Aikido, Endor Labs, and Socket, confirm that the malicious code resides in ‘telnyx/_client.py’. This code becomes active when the package is loaded into a Python application, targeting systems across Windows, Linux, and macOS platforms. The attack chain on Linux and macOS involves a three-step process that starts with delivery through audio steganography, followed by in-memory execution of the malware, and concludes with encrypted data exfiltration.

On Windows, the attack involves downloading a file named ‘hangup.wav’ from a command-and-control server, extracting an executable from it, and placing it in the Startup folder as ‘msbuild.exe’. This allows the malware to persist through system reboots. In contrast, the Linux and macOS systems receive a different .WAV file, ‘ringtone.wav’, which extracts a collector script to harvest sensitive data, subsequently transmitting it to a remote server.

Analysis of the Attack Techniques

This attack stands out due to its use of audio steganography, a technique that conceals the final payload within a .WAV file, thereby evading traditional detection mechanisms. The method avoids using raw executables or base64 blobs that are easily flagged by network and endpoint detection tools. The origin of the PyPI token used by TeamPCP remains unclear, though it may have been acquired during a prior compromise of the litellm package.

Endor Labs researchers suggest that TeamPCP likely harvested environment variables and shell histories from systems using litellm, potentially capturing the Telnyx PyPI token in the process. Notably, the attack lacks a persistence mechanism on Linux and macOS, opting instead for a rapid ‘smash-and-grab’ operation that deletes its traces post-execution.

Recommendations and Wider Implications

Developers are advised to conduct a thorough audit of their Python environments, specifically checking for the presence of Telnyx 4.87.1 or 4.87.2 in their requirements. If found, these versions should be replaced immediately with a secure alternative. It is also recommended to rotate all compromised credentials and block the identified command-and-control domains.

This breach is part of an expansive campaign by TeamPCP, leveraging collaborations with other cybercriminal groups to conduct extortion and ransomware attacks. The incident highlights the evolving threat landscape, where attackers are increasingly targeting the supply chain as a vector for initiating attacks. As such, organizations must scrutinize any tool that has broad access in CI/CD environments, as these can serve as potential entry points for future threats.

The Hacker News Tags:audio steganography, Cybersecurity, Linux, macOS, Malware, PyPI, security breach, supply chain attack, TeamPCP, Telnyx, Windows

Post navigation

Previous Post: Critical Flaw in Kea DHCP Poses Remote Crash Risk
Next Post: Iranian Hackers Breach FBI Director’s Email

Related Posts

Critical 18-Year NGINX Vulnerability Enables Remote Code Execution Critical 18-Year NGINX Vulnerability Enables Remote Code Execution The Hacker News
PCI DSS Compliance: Checkout Page Scripts Under Scrutiny PCI DSS Compliance: Checkout Page Scripts Under Scrutiny The Hacker News
Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams The Hacker News
Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans The Hacker News
Can Your Security Stack See ChatGPT? Why Network Visibility Matters Can Your Security Stack See ChatGPT? Why Network Visibility Matters The Hacker News
AI’s Role in Security: Validation Still Key AI’s Role in Security: Validation Still Key The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID
  • 800 Malicious npm Packages Spread Cross-Platform Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID
  • 800 Malicious npm Packages Spread Cross-Platform Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark