Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

TeamPCP compromised Telnyx Python SDK versions 4.87.1 and 4.87.2 on PyPI, embedding a steganographic payload in WAV audio files that executes on package import and exfiltrates SSH keys, cloud credentials, and Kubernetes secrets. No CVE has been assigned. Any environment that installed either version should treat all credentials accessible from that environment as compromised. This is the highest-priority item in this rollup by priority score.

Author

Tech Jacks Solutions