Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package

On March 27, 2026, TeamPCP injected a WAV steganography-based credential stealer into two releases of the telnyx Python SDK on PyPI. The group was identified by shared cryptographic signatures and exfiltration methods matching their earlier litellm compromise.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Distributed via PyPI; affected all users who installed the malicious telnyx SDK releases. Scope depends on adoption of the two compromised releases.
Ecosystems
Attack vectors
Threat actor
Affected entities
  • telnyxPython SDK; two releases compromised with WAV steganography credential stealer

On March 27, 2026, the TeamPCP threat actor group compromised two releases of the telnyx Python SDK on PyPI by injecting malicious code implementing a credential stealer using WAV steganography. The attack was disclosed via issue team-telnyx/telnyx-python#235.

TeamPCP was identified as the same threat actor behind the litellm supply chain compromise, which occurred approximately three days earlier (around March 24, 2026). Attribution was based on overlapping indicators of compromise: a shared RSA-4096 public key, identical encryption schemes used in both attacks, and the distinctive tpcp.tar.gz exfiltration signature present in both incidents.

The use of WAV steganography as a credential exfiltration mechanism represents a sophisticated obfuscation technique designed to evade detection and hide stolen credentials within audio data.

Indicators of compromise

Packages
  • telnyx

Remediation

  • Immediately revoke and rotate any credentials that may have been exposed through systems running the compromised telnyx SDK releases
  • Audit PyPI package installation logs to identify which versions of telnyx were deployed and when
  • Update to a patched version of telnyx Python SDK once released by Telnyx
  • Scan systems for indicators of the tpcp.tar.gz exfiltration artifact and associated RSA-4096 key signatures
  • Review authentication logs for suspicious activity during the window when malicious releases were available on PyPI

Sources

  1. TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package · StepSecurity

Cite this entry

"TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed March 27, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/teampcp-plants-wav-steganography-credential-stealer-in-telnyx-pypi-package-iwek9d

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in fastapii (PyPI)

    The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    2026 08 FlasqPyPITyposquattingCompromised package
  2. containedcritical

    Malicious code in idnna (PyPI)

    A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    PyPITyposquattingCompromised package
  3. containedcritical

    Malicious code in pydanticc (PyPI)

    The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    2026 08 FlasqPyPITyposquattingCompromised package
  4. containedcritical

    Malicious code in flasq (PyPI)

    A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    PyPITyposquattingCompromised package