WordPress Malware Alert: Backdoored Telnyx Package Disguised in WAV

Date:

Cybersecurity Alert: Malicious Telnyx Package Compromises Developers’ Data

Today, the TeamPCP hacking group launched a supply-chain attack on the Telnyx package available on the Python Package Index (PyPI). They uploaded backdoored versions (4.87.1 and 4.87.2) of this popular software development kit, which is used by developers to integrate Telnyx communication services into applications.

The attack impacts a significant number of developers, as the Telnyx package garners over 740,000 downloads monthly. The malicious code, hidden in a WAV file, stealthily steals sensitive data such as SSH keys and cloud tokens from infected systems, with the potential for severe data breaches.

To protect against this threat, developers should immediately roll back to the clean version (4.87.0) and rotate all compromised secrets. Given the nature of the attack and the extent of the threat, the risk level is assessed as High.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...