The telnyx Python SDK on PyPI was compromised after malicious versions 4.87.1 and 4.87.2 were published with code injected into telnyx/_client.py, causing malware to run automatically when the package was imported. Researchers linked the activity to TeamPCP, tying it to the same supply-chain campaign that previously hit projects including Trivy, LiteLLM, npm packages, and Checkmarx assets. The tainted releases fetched second-stage payloads hidden in WAV files such as hangup.wav and ringtone.wav from 83.142.209.203:8080, using steganography to conceal the malware.

Trace attribution and downstream blast radius.
16 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-02, PyPI disclosed that the LiteLLM and telnyx malicious releases were enabled by exposed API tokens through an exploited Trivy dependency and said it quarantined the malicious packages within hours. PyPI also reported that the malicious LiteLLM versions were downloaded more than 119,000 times and issued mitigation guidance including lock files with hashes, Trusted Publishers, secure CI/CD practices, dependency cooldowns, and broader 2FA use.
By 2026-03-30, Databricks was reportedly investigating an alleged compromise connected to credentials harvested in the TeamPCP supply-chain campaign. If confirmed, it would mark the first major downstream cloud-platform victim disclosed beyond the originally compromised software vendors.
By 2026-03-28, researchers said no new package compromises had been confirmed in the 48 hours following the Telnyx PyPI disclosure, the first such pause since the campaign began on March 19. They assessed that TeamPCP may be shifting from rapid supply-chain expansion toward monetizing previously stolen credentials, while warning the campaign could resume.
The campaign update reported a CISA Known Exploited Vulnerabilities catalog change that corrected the remediation deadline for CVE-2026-33634 and added CVE-2026-33017. This was a separate defensive and vulnerability-management development mentioned alongside the TeamPCP reporting.
On 2026-03-27, the update said GitHub introduced a new Actions security roadmap in response to CI/CD-focused software supply-chain attacks highlighted by the broader TeamPCP campaign. This represented a platform-level defensive response to the wave of compromises affecting developer ecosystems.
On 2026-03-27, reporting said the LiteLLM compromise stemmed from the targeted takeover of CEO Krish Dholakia’s personal GitHub account. The update added forensic details that the malicious LiteLLM package used Python .pth auto-execution, typosquatted C2 infrastructure, Kubernetes token theft attempts, and broad credential harvesting.
On 2026-03-27, reporting said LAPSUS$ had claimed a breach of AstraZeneca using access linked to credentials harvested in the TeamPCP supply-chain campaign. The claim was described as the first named victim disclosure tied to downstream exploitation of TeamPCP-compromised access.
Following disclosure, defenders were told to treat any host that installed telnyx 4.87.1 or 4.87.2 as compromised, remove those versions, downgrade to 4.87.0, rotate credentials, and investigate persistence and network connections to the identified attacker infrastructure.
On 2026-03-27, researchers reported that TeamPCP had partnered with the Vect ransomware-as-a-service operation and BreachForums to industrialize ransomware deployment using access and credentials stolen through earlier supply-chain compromises. The report framed this as a downstream monetization escalation beyond the package compromises themselves.
Researchers reported that the compromised package fetched second-stage malware hidden in WAV files such as hangup.wav or ringtone.wav from 83.142.209.203:8080. On Windows, the malware dropped a persistent msbuild.exe in Startup, while Linux and macOS ran a collector that encrypted and exfiltrated stolen data.
Analysis attributed the malicious telnyx packages to TeamPCP with high confidence based on a shared RSA-4096 public key, the recurring tpcp.tar.gz exfiltration signature, and the same AES/RSA hybrid encryption workflow seen in earlier supply-chain incidents. The compromise was described as part of TeamPCP's broader campaign affecting other software ecosystems and vendors.
PyPI quarantined malicious telnyx versions 4.87.1 and 4.87.2 at 10:13 UTC on 2026-03-27 after roughly 6.5 hours of exposure. This provides a platform-side containment timestamp for the Telnyx supply-chain compromise.
Also on 2026-03-27, attackers published telnyx version 4.87.2 with the malicious code still present. This release fixed the earlier bug, enabling both Windows and Linux/macOS infection paths.
On 2026-03-27, attackers published malicious telnyx version 4.87.1 to PyPI, injecting code into telnyx/_client.py that executed on import. This version included a bug that prevented the Windows payload path from running correctly.
Before the compromise, telnyx version 4.87.0 was the last known clean release on PyPI. Later guidance recommended pinning or downgrading to this version.
Telnyx disclosed that malicious telnyx versions 4.87.1 and 4.87.2 were available on PyPI for roughly 27 minutes and were downloaded 756 times before removal. The company said its API, internal systems, and customer data were not affected by the supply-chain compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
21 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourceblog.pypi.org
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourceendorlabs.com
Open sourceisc.sans.edu
Open sourceresearch.jfrog.com
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.