Cybersecurity Alert: Malicious Telnyx Package Compromises Developers’ Data
Today, the TeamPCP hacking group launched a supply-chain attack on the Telnyx package available on the Python Package Index (PyPI). They uploaded backdoored versions (4.87.1 and 4.87.2) of this popular software development kit, which is used by developers to integrate Telnyx communication services into applications.
The attack impacts a significant number of developers, as the Telnyx package garners over 740,000 downloads monthly. The malicious code, hidden in a WAV file, stealthily steals sensitive data such as SSH keys and cloud tokens from infected systems, with the potential for severe data breaches.
To protect against this threat, developers should immediately roll back to the clean version (4.87.0) and rotate all compromised secrets. Given the nature of the attack and the extent of the threat, the risk level is assessed as High.
Source: View Original Report
