Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Threat actor TeamPCP has compromised two versions of the telnyx Python package on PyPI (4.87.1, 4.87.2), embedding credential-harvesting malware inside WAV audio files to evade detection, part of a confirmed multi-package supply chain campaign that has also hit litellm, Trivy, and KICS. Any CI/CD pipeline that installed these packages should be treated as fully compromised; all secrets, tokens, and credentials accessible in those environments are at risk of exfiltration. Reporting from Datadog and Aikido links TeamPCP to LAPSUS$ and ransomware group Vect based on TTP overlap and campaign scope; attribution confidence is moderate pending independent corroboration, raising the likelihood of follow-on ransomware or extortion beyond initial credential theft.

Author

Tech Jacks Solutions