Major compromise of the telnyx PyPI library could put millions of users at risk


  • JFrog reports that the Telnyx PyPI package was poisoned with malware by TeamPCP
  • Malicious update delivered hidden .wav payload that implemented infostealer and persistence mechanisms
  • Users are advised to downgrade, block C2 communication, rotate credentials and scan for persistence

Telnyx, a popular PyPI package with real-time communication features, was recently poisoned and used to serve malware to its users, experts have warned.

A report by security researchers JFrog, along with other independent security experts, notes how Telnyx, as a cloud platform that lets developers add real-time communication features to apps, such as voice and messaging, provides APIs and tools to build solutions such as calling systems and SMS-based services.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top