TeamPCP strikes again - telnyx 4.87.1 and 4.87.2 on PyPI are malicious
Posted by No_Plan_3442@reddit | programming | View on Reddit | 63 comments
Same actor, same RSA key, same `tpcp.tar.gz` exfiltration header as the litellm compromise last week.
This time they injected into `telnyx/_client.py` \- triggers on `import telnyx`, no user interaction needed. New trick: payload is hidden inside WAV audio files using steganography to bypass network inspection.
On Linux/macOS: steals credentials, encrypts with AES-256 + RSA-4096, exfiltrates to their C2. On Windows: drops a persistent binary in the Startup folder named `msbuild.exe`.
They even pushed a quick 4.87.2 bugfix to fix a casing error that was breaking the Windows path. These folks are paying attention.
Pin to `telnyx==4.87.0`. Rotate creds if you installed either version.
Full analysis with IoCs here [https://safedep.io/malicious-telnyx-pypi-compromise/](https://safedep.io/malicious-telnyx-pypi-compromise/)
63 Comments
sailing67@reddit
programming-ModTeam@reddit
Worth_Trust_3825@reddit
palecvstepler@reddit
programming-ModTeam@reddit
pip25hu@reddit
AlSweigart@reddit
pip25hu@reddit
tedivm@reddit
tedivm@reddit
dsffff22@reddit
tedivm@reddit
dsffff22@reddit
tedivm@reddit
dsffff22@reddit
tedivm@reddit
dsffff22@reddit
N1ghtCod3r@reddit
tedivm@reddit
TOMZ_EXTRA@reddit
tedivm@reddit
BattleRemote3157@reddit
edeltoaster@reddit
BattleRemote3157@reddit
GroundbreakingMall54@reddit
snotfart@reddit
ExF-Altrue@reddit
saynay@reddit
QuickQuirk@reddit
ExF-Altrue@reddit
QuickQuirk@reddit
ExF-Altrue@reddit
QuickQuirk@reddit
axonxorz@reddit
Enerbane@reddit
ivosaurus@reddit
saynay@reddit
drislands@reddit
Enerbane@reddit
drislands@reddit
drumallnight@reddit
Enerbane@reddit
f311a@reddit
cinyar@reddit
wRAR_@reddit
-Nyarlabrotep-@reddit
spareminuteforworms@reddit
AbrahelOne@reddit
ExF-Altrue@reddit
Worth_Trust_3825@reddit
ExF-Altrue@reddit
Worth_Trust_3825@reddit
ExF-Altrue@reddit
axkotti@reddit
tedivm@reddit
coderanger@reddit
tedivm@reddit
coderanger@reddit
Acrobatic_Camp_2758@reddit
Mooshux@reddit
BlueGoliath@reddit
ExF-Altrue@reddit
UnbeliebteMeinung@reddit