On 27 March 2026 two unauthorised versions of the official Telnyx Python SDK, telnyx 4.87.1 and 4.87.2, were published to PyPI with a credential stealer hidden inside WAV audio files. Telnyx says the first version went live at 03:51 UTC and both were quarantined by 10:13 UTC. Anyone who installed or upgraded the package in that window, or pulled it in as an unpinned dependency, should treat the environment as compromised. Researchers attribute the attack to TeamPCP, the group behind the Trivy and LiteLLM compromises earlier that month. Telnyx says its own platform, APIs and infrastructure were not compromised and that no customer data was accessed. It has not said how the attacker obtained its PyPI publishing credentials. Endor Labs believes the most likely route was the LiteLLM compromise three days earlier, whose stealer swept environment variables and secrets from every system that imported it.
Key takeaways
- Malicious telnyx 4.87.1 and 4.87.2 were on PyPI for about six hours on 27 March 2026. StepSecurity says the package had about 742,000 downloads in the previous 30 days.
- The attacker published through Telnyx's legitimate PyPI release line using publishing credentials whose source Telnyx is still investigating. Endor Labs suspects they were harvested in the LiteLLM compromise.
- The code ran on
import telnyx, fetched WAV files from the attacker's server and decoded a credential harvester on Linux and macOS and a persistent executable on Windows. - Telnyx confirmed the malicious releases and says its platform and customer data were not affected. The risk sits with developers and pipelines that installed the bad versions.
- The identity lesson: a stolen package-publishing credential turns one breach into the next, so publishing tokens need to be short-lived, scoped and kept out of environments that run third-party code.
At a glance
| Organisation | Telnyx (communications platform; telnyx Python SDK on PyPI) and developers and pipelines that installed it |
|---|---|
| When | Malicious versions live from 03:51 to 10:13 UTC on 27 March 2026; disclosed the same day |
| Attacker | TeamPCP, according to StepSecurity and other researchers |
| Entry point | Unauthorised publishing to PyPI with Telnyx's publishing credentials; how they were obtained is under investigation |
| Identities abused | The telnyx PyPI publishing credential; then cloud credentials, SSH keys, Kubernetes tokens, registry tokens and API keys on victim systems |
| Impact | Credential theft from environments that installed 4.87.1 or 4.87.2; Telnyx platform and customer data not affected, according to Telnyx |
| Category | NHI. Incident class: confirmed NHI breach (publishing credential abused to ship a credential stealer) |
What happened
Telnyx sells voice, messaging and networking APIs, and its Python SDK is how many developers call them. On 27 March 2026, telnyx 4.87.1 was published to PyPI at 03:51:28 UTC, followed shortly after by 4.87.2. Neither came from Telnyx. In its security notice, Telnyx said both versions contained malicious code, that both were quarantined by 10:13 UTC, and that the incident was part of a broader campaign that also hit Trivy, Checkmarx and LiteLLM. StepSecurity wrote that "TeamPCP injected a WAV steganography-based credential stealer into two releases of the telnyx Python SDK on PyPI."
StepSecurity found 74 lines added to telnyx/_client.py, so the code ran as soon as the package was imported. On Linux and macOS it started a detached process that downloaded a file called ringtone.wav, extracted a Python harvester hidden in the audio data and ran it in memory. The harvested data was encrypted with AES-256-CBC and RSA-4096, packed as tpcp.tar.gz and posted to the attacker's server. On Windows it downloaded hangup.wav, decoded an executable and dropped it into the Startup folder as msbuild.exe. A casing bug meant the Windows path did not run in 4.87.1. The attacker fixed it in 4.87.2. The Hacker News adds that the malware could abuse Kubernetes service account tokens to deploy a privileged pod to every node.
Telnyx's statement was clear on scope: "The Telnyx platform, APIs, and infrastructure were not compromised." It added: "No customer data was accessed through this incident." It removed the versions and said it was investigating how publishing credentials were obtained. The Hacker News reported that how TeamPCP got the token is unknown. Endor Labs researchers Kiran Raj and Rachana Misal said: "We believe the most likely vector is the litellm compromise itself". Their reasoning was that the LiteLLM stealer collected environment variables, .env files and shell histories from every system that imported it, so any developer machine or pipeline holding both LiteLLM and a telnyx publishing token would have exposed it.
Timeline
| Date | Event |
|---|---|
| 19 March 2026 | The Trivy supply chain attack begins the TeamPCP March wave. |
| 24 March 2026 | Malicious LiteLLM versions are published to PyPI, carrying a stealer that sweeps environment secrets. |
| 26 March 2026 | telnyx 4.87.0, the last clean release, is published to GitHub (StepSecurity). |
| 27 March 2026 | telnyx 4.87.1 is published to PyPI at 03:51 UTC, followed by 4.87.2. |
| 27 March 2026 | Both versions are quarantined by 10:13 UTC; Telnyx publishes its security notice and researchers publish analyses. |
How it happened: the identity attack path
- Credentials harvested upstream. TeamPCP's earlier compromises of Trivy and LiteLLM stole secrets from developer machines and CI runners. Endor Labs believes the telnyx publishing credential was among them, though Telnyx has not confirmed the source.
- A publishing identity reused. With a valid credential, the attacker published new versions under the genuine telnyx project, so PyPI and every installer treated them as official.
- Code that runs on import. The injected code ran the moment an application or test imported the SDK, with the privileges of that process.
- Payload hidden in audio. The second stage was fetched as WAV files. Ossprey Security, quoted by The Hacker News, framed this as an alternative to hosting "a raw executable or a base64 blob on the C2".
- Secrets collected for the next round. The harvester took cloud keys, SSH keys, tokens and environment secrets from each victim, the same kind of material that likely enabled this attack.
Impact
- Confirmed: two malicious telnyx releases on PyPI for about six hours, according to Telnyx.
- Not affected: Telnyx's platform, APIs, infrastructure and customer data, according to Telnyx.
- Potential: theft of any secret reachable from environments that installed 4.87.1 or 4.87.2, including API keys, database credentials, cloud tokens, SSH keys and registry tokens. No count of affected installs has been published.
- Wider: credentials taken from telnyx users could feed further package compromises, the pattern seen across the TeamPCP campaign.
What this means for NHI governance
The telnyx compromise is a chain-reaction breach. A publishing credential is a non-human identity with one job, to push new versions of a package. Whoever holds it can ship code to every downstream user. If that credential lives as a long-lived token on a developer machine or in a CI environment that also runs third-party packages, any stealer that lands there can take it. That is the path Endor Labs believes was used here.
Defending against this means narrowing who and what can publish, and how long a publishing credential lasts. PyPI's trusted publishing ties a release to a specific CI workflow through short-lived OIDC tokens rather than stored API tokens. Where tokens remain, they should be scoped to one project and kept out of build steps that install and run dependencies. See our CI/CD Pipeline Identity Security Guide and Secrets Management Guide.
For consumers, the lesson is the same as for LiteLLM and xinference: pin versions, delay adoption of brand-new releases, and assume that anything installed during an exposure window has seen every secret in its environment.
Recommendations
- Check for the malicious versions now. Run
pip show telnyxacross developer machines, images and pipelines. Telnyx's advice: "If the version shown is 4.87.1 or 4.87.2, treat the environment as compromised." - Rotate every secret the environment could reach. Rotate API keys, database credentials, cloud tokens, SSH keys and secrets in environment variables or config files. See our Leaked Credential Response Playbook.
- Move publishing to trusted publishing. Replace stored PyPI API tokens with OIDC trusted publishing tied to a single workflow. See our CI/CD Pipeline Identity Security Guide.
- Keep publishing credentials away from third-party code. Do not expose release tokens to jobs that install dependencies or run scanners, and scope each token to one project. See our API Key Management Guide.
- Pin and delay dependency updates. Pin exact versions with hashes and apply a cooldown before adopting new releases, so short-lived malicious versions never arrive.
- Check Kubernetes and Windows hosts. Look for unexpected privileged pods and for
msbuild.exein Startup folders on machines that ran the affected versions.
Frequently asked questions
Which telnyx versions were malicious?
telnyx 4.87.1 and 4.87.2 on PyPI, published on 27 March 2026 and quarantined by 10:13 UTC the same day. Telnyx advises downgrading to 4.87.0 and treating any environment that ran the malicious versions as compromised.
Was Telnyx itself breached?
Telnyx says its platform, APIs and infrastructure were not compromised and no customer data was accessed. The attacker did, however, publish through Telnyx's PyPI release channel, and Telnyx is investigating how its publishing credentials were obtained.
How is the telnyx attack linked to LiteLLM?
Researchers attribute both to TeamPCP, and the telnyx payload uses the same encryption and archive format as earlier waves. Endor Labs believes the telnyx publishing credential was most likely stolen by the LiteLLM stealer three days earlier, but this has not been confirmed.
Related NHI Mgmt Group resources
LiteLLM PyPI Package Breach 2026 · Trivy supply chain attack 2026 · xinference PyPI compromise 2026 · CI/CD Pipeline Identity Security Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Package-publishing credentials are some of the most powerful non-human identities an organisation owns. We help teams find them, move them to short-lived trusted publishing and build the response steps for when a dependency turns hostile. See our NHI and AI agent security training.
References
- Telnyx: Telnyx Python SDK: Supply Chain Security Notice (27 March 2026)
- StepSecurity: TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package (27 March 2026)
- The Hacker News: TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files (27 March 2026)
- GitGuardian: No Off Season: Three Supply Chain Campaigns Hit npm, PyPI, and Docker Hub in 48 Hours (23 April 2026)