WordPress Malware Alert: Backdoored Telnyx Package Disguised in WAV

Date:

Cybersecurity Alert: Malicious Telnyx Package Compromises Developers’ Data

Today, the TeamPCP hacking group launched a supply-chain attack on the Telnyx package available on the Python Package Index (PyPI). They uploaded backdoored versions (4.87.1 and 4.87.2) of this popular software development kit, which is used by developers to integrate Telnyx communication services into applications.

The attack impacts a significant number of developers, as the Telnyx package garners over 740,000 downloads monthly. The malicious code, hidden in a WAV file, stealthily steals sensitive data such as SSH keys and cloud tokens from infected systems, with the potential for severe data breaches.

To protect against this threat, developers should immediately roll back to the clean version (4.87.0) and rotate all compromised secrets. Given the nature of the attack and the extent of the threat, the risk level is assessed as High.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...