Signal
TeamPCP compromises Telnyx PyPI package with malware hidden in WAV files
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-03-27 13:46 UTCUpdated 2026-03-27 21:13 UTC
redditrss
supply_chainmalwarecredential_stealingpypiincident_response
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.4 top sources shown
Overview
The threat actor TeamPCP has expanded its supply chain attacks by compromising the Telnyx Python package on PyPI.
Entities
TelnyxEndor LabsSocketSANS ISCCISATelnyx AI Voice AgentVect ransomware
Score total
2.01
Momentum 24h
6
Evidence documents
-
Independent publishers
-
Independent origins
-
Primary sources
-
Secondary sources
-
Source types
-
Duplicate ratio
0%
Why now
- Malicious Telnyx package versions were published on PyPI on March 27, 2026, requiring immediate attention.
- TeamPCP's expanding campaign includes ransomware affiliates and named victims, increasing risk exposure.
- Security communities have just released updated detection tools and advisories to respond to this threat.
Why it matters
- Supply chain attacks on popular Python packages risk widespread credential theft and software compromise.
- Malware hidden in audio files demonstrates advanced evasion techniques by threat actors.
- Detection tools and advisories enable defenders to identify and mitigate this ongoing threat.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- TeamPCP compromised the Telnyx Python package on PyPI by publishing malicious versions 4.87.1 and 4.87.2 containing credential-stealing malware hidden in WAV files.
- The TeamPCP campaign is part of a wider supply chain compromise involving ransomware affiliates and named victims, with detection tools and advisories published by SANS ISC and CISA.
How sources frame it
- The Hacker News: neutral
- Help Net Security: neutral
- SANS ISC: neutral
All evidence
All evidence
Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
BleepingComputer · bleepingcomputer.com · 2026-03-27 21:13 UTC
TamPCP scope is wider than the original Checkmarx report
Reddit · reddit.com · 2026-03-27 19:27 UTC
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files
Thehackernews · thehackernews.com · 2026-03-27 16:53 UTC
TeamPCP Targets Telnyx Package in Latest PyPI Software Supply Chain Attack
Infosecurity Magazine · infosecurity-magazine.com · 2026-03-27 15:06 UTC
TeamPCP Supply Chain Campaign: Update 002 - Telnyx PyPI Compromise, Vect Ransomware Mass Affiliate Program, and First Named Victim Claim, (Fri, Mar 27th)
Sans · isc.sans.edu · 2026-03-27 14:22 UTC
TeamPCP strikes again: Backdoored Telnyx PyPI package delivers malware
Helpnetsecurity · helpnetsecurity.com · 2026-03-27 13:46 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 6Origin domains: 6Duplicates: -
Showing 6 / 6
Top publishers (this list)
- BleepingComputer (1)
- Reddit (1)
- Thehackernews (1)
- Infosecurity Magazine (1)
- Sans (1)
- Helpnetsecurity (1)
Top origin domains (this list)
- bleepingcomputer.com (1)
- reddit.com (1)
- thehackernews.com (1)
- infosecurity-magazine.com (1)
- isc.sans.edu (1)
- helpnetsecurity.com (1)