Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Telnyx Python SDK Compromised to Deliver Credential-Stealing Malware

http://83.142.209.203:8080/ringtone.wav

TLP:CLEAR
Active

URL

Description

A supply chain attack affecting the telnyx Python package on PyPI has been identified. Malicious versions 4.87.1 and 4.87.2 contained embedded credential-harvesting malware. The attack employs a three-stage runtime chain on Linux/macOS using audio steganography for delivery, in-memory execution of a data harvester, and encrypted exfiltration. On Windows, it drops a persistent binary in the Startup folder. The malware uses sophisticated techniques including fileless execution, hybrid encryption, and anti-forensics measures. The threat actor, TeamPCP, demonstrates high operational security and cryptographic awareness. Developers are advised to audit environments, rotate credentials, and check for indicators of compromise.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Telnyx Python SDK Compromised to Deliver Credential-Stealing Malware
Pattern Type
STIX
Confidence
75%
Valid From
May 3, 2026 00:55
Total Sightings
0
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of http://83.142.209.203:8080/ringtone.wav

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.