ended3월 27일· 4 sources
PyPI Compromised: telnyx Packages Weaponized with Steganography-Hidden Malware
PyPI의 telnyx 패키지 악용한 스테가노그래피 기반 악성코드 유포
Why it matters
Malicious versions of the telnyx Python package on PyPI employed sophisticated steganography to embed malware within WAV audio files, evading standard network inspection tools. The attack delivered platform-specific payloads that steal credentials on Linux/macOS and establish persistence on Windows, while the same threat actor was recently linked to the litellm compromise. This incident underscores how supply chain attackers are rapidly evolving tactics to bypass security measures and infiltrate development environments.
4
Sources
+0
24h
—
Growth
173d
Active
PyPI compromiseCheckmarxPackage verificationsupply chainTelnyxSteganographysupply chain attack
Sources
reddit_prog
TeamPCP strikes again - telnyx 4.87.1 and 4.87.2 on PyPI are malicious3월 27일
hackernewsTelnyx Python SDK: Supply Chain Security Notice3월 28일
hackernewsThe telnyx packages on PyPI have been compromised3월 28일
devtoSupply Chain Security: How the Telnyx PyPI Compromise Happened and How to Protect Your Projects3월 28일