🌍 Top Stories🤖 Tech💰 Finance🧬 Health⚡ Energy⚽ Sports🎬 Culture
Tech & Science

TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files

By The Hacker News · 2026-03-27
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files
Why it matters: This highlights critical vulnerabilities in open-source supply chains, demanding urgent security enhancements.
TeamPCP, a known threat actor, has expanded its supply chain attacks by compromising the telnyx Python package on PyPI, pushing two malicious versions (4.87.1 and 4.87.2) designed to steal sensitive data. This incident follows their previous targeting of Trivy, KICS, and litellm, indicating a persistent and evolving threat to open-source software supply chains.

Share this story

More tech & science → Read original →

Get tech & science in your inbox

The best stories, summarized daily. Free.

No spam. Unsubscribe anytime.