Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Threat actor TeamPCP compromised the official Telnyx Python SDK on PyPI, publishing malicious versions 4.87.1 and 4.87.2 that steal SSH keys, cloud credentials, and Kubernetes secrets from any environment that installed them. Any organization using the Telnyx Python SDK in development pipelines, CI/CD systems, or production infrastructure may have had credentials silently exfiltrated. The Telnyx SDK is widely used in the Python developer community, making the potential scope significant, and because the malware conceals its payload inside audio files, standard file-scanning tools likely missed it.

Author

Tech Jacks Solutions