| Quick heads up: telnyx versions 4.87.1 and 4.87.2 on PyPI were malicious. Importing the package is enough to execute code. The odd part is how the payload is delivered. It pulls a .wav file, then extracts and reconstructs the actual payload from the audio data (base64 + XOR). The file itself looks like normal audio. Windows drops a persistent msbuild.exe in Startup. Linux/macOS runs a staged script, encrypts collected data, and sends it out. More info and breakdown linked. [link] [comments] |
Intelligence View
⚡ tsecurity.de Intelligence
Telnyx PyPI package compromise (TeamPCP). Credential exfil via fake .wav files in supply chain attack
Quick heads up: telnyx versions 4.87.1 and 4.87.2 on PyPI were malicious. Importing the package is enough to execute code. The odd part is how the payload is delivered. It pulls a .wav file, then extracts and reconstructs the actual…
Reagiere als Erste:r — dein Feedback zählt!
2. Cyber Threat Intelligence & Forensik
CTI Threat Relationship Graph2 Knoten / 1 Relationen