Home TechnologyTeamPCP Targets Telnyx Package in Latest PyPI Soft...
Technology⭐ Featured

TeamPCP Targets Telnyx Package in Latest PyPI Software Supply Chain Attack

Socket and Endor Labs discovered a new TeamPCP campaign leading to the delivery of credential-stealing malware

6 April 2026 at 01:56 pm
1 views
TeamPCP Targets Telnyx Package in Latest PyPI Software Supply Chain Attack

In a recent development in the world of cybersecurity, Socket and Endor Labs have uncovered a new campaign by the notorious TeamPCP group, targeting the Telnyx package on PyPI, the Python Package Index. This attack highlights the vulnerabilities in software supply chains and the need for enhanced security measures in open-source ecosystems.

The TeamPCP group, known for its extensive malware distribution activities, has been identified as the perpetrator behind this latest attack. The group has a history of exploiting software supply chains to deliver malicious payloads, often targeting organizations with critical infrastructure or sensitive data. This new campaign underscores the ongoing threat posed by such groups and the importance of vigilance in protecting digital assets.

The attack involves the Telnyx package, a popular Python library used for building and managing cloud-native applications. PyPI, the repository where the package is hosted, is a common target for attackers due to its widespread use and the ease with which packages can be manipulated. In this case, the malicious code was introduced in an update to the Telnyx package, allowing it to steal credentials from unsuspecting users.

Socket and Endor Labs first detected the malware through their continuous monitoring of the software supply chain. The credential-stealing malware, once executed, would harvest sensitive information such as usernames, passwords, and other authentication details, posing a significant risk to organizations relying on the Telnyx package. The malware's ability to infiltrate systems through legitimate-looking software updates highlights the challenge of maintaining security in open-source environments.

Upon discovering the compromise, the security researchers promptly reported the issue to the Telnyx developers and the PyPI community. The response from the Telnyx team was swift, with a new, clean version of the package being released to mitigate the threat. This rapid action is crucial in preventing further damage and demonstrates the importance of collaboration between developers, security researchers, and the open-source community in addressing such vulnerabilities.

This incident serves as a stark reminder of the risks associated with software supply chains. While open-source software is often praised for its transparency and collaborative nature, it also presents opportunities for attackers to infiltrate systems. Organizations must therefore adopt robust security practices, including regular updates, dependency scanning, and the use of trusted package sources, to safeguard against such threats.

The TeamPCP campaign targeting the Telnyx package is a clear example of how attackers exploit vulnerabilities in software supply chains to deliver malware. As cyber threats continue to evolve, it is essential for developers, organizations, and security professionals to remain vigilant and proactive in protecting against such attacks. The collaboration between Socket, Endor Labs, and Telnyx demonstrates the critical role that security research and rapid response can play in mitigating the impact of these threats.

In conclusion, the recent discovery of the TeamPCP campaign targeting the Telnyx package on PyPI underscores the ongoing challenges in securing software supply chains. While open-source software offers numerous benefits, it also requires enhanced vigilance and robust security measures to protect against malicious actors. The swift response from the Telnyx team and the collaboration between security researchers and developers are crucial in addressing these threats and ensuring the integrity of the open-source ecosystem. As cyber threats continue to evolve, it is imperative for all stakeholders to remain committed to improving security practices and fostering a culture of vigilance in the face of these challenges.

📰 Related News
Ekaya Banaras Founder Palak Shah’s ₹40 Lakh Billboard Mistake Became a Masterclass in Startup Marketing
Ekaya Banaras Founder Palak Shah’s ₹40 Lakh Billboard Mistake Became a Masterclass in Startup Marketing
Ekaya Banaras founder Palak Shah recently opened up about one of the most expensive mistakes she made while building her luxury textile brand. During the early years of the company, Shah rented a premium billboard near Delhi’s DLF Emporio to increase brand visibility. However, after forgetting to cancel the campaign, the hoarding reportedly continued running for months — resulting in losses of nearly ₹40 lakh. The incident has now become a viral example of how small operational oversights can turn into costly business lessons for startups and entrepreneurs.
28 May
Betting On AI: Jensen Huang And NVIDIA’s Rise To The Top
Betting On AI: Jensen Huang And NVIDIA’s Rise To The Top
Before AI was inevitable, it was a gamble—and Jensen Huang went all in.
14 Apr
Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1 bring confidential computing to bare metal and AI workloads
Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1 bring confidential computing to bare metal and AI workloads
Red Hat is excited to announce the release of Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1, marking a major leap forward in our confidential computing journey. These releases graduate confidential containers on bare metal from …
14 Apr
Large AI firms hoovering maximum funding, not enough for smaller startups: Y Combinator’s Ankit Gupta
Large AI firms hoovering maximum funding, not enough for smaller startups: Y Combinator’s Ankit Gupta
YC Startup School: India’s talent pool across colleges and universities are key for building next-gen startups, which is what YC is looking to tap into. It wants to target entrepreneurs building for global markets, focussed on fintech, consumer, B2B, and ecom…
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC-RESULTS/ (PREVIEW, PIX):PREVIEW-TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
Any profit result ‌above T$505.7 billion would mark the company's highest-ever quarterly net income ​and its ninth consecutive quarter of profit growth
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
On Thursday, ​TSMC is expected to report a net profit of $17.1 billion for the quarter, according to an LSEG SmartEstimate compiled from 19 analysts. The war in the Middle East threatens to disrupt the supply of production materials for semiconductors such as…
14 Apr
If we can’t kick the habit, how do we manage AI’s energy needs?
If we can’t kick the habit, how do we manage AI’s energy needs?
One can only hope that OpenAI’s Sam Altman was joking when he sought to justify the immense energy consumption of artificial intelligence
14 Apr
What caused Nvidia Blackwell GPU prices to spike? #tech
What caused Nvidia Blackwell GPU prices to spike? #tech
Blackwell GPU hourly “rent” surges on agentic AI demand A compute pricing index tracking hourly costs for Nvidia Blackwell GPUs shows a sharp climb: hourly rental hit $4.08 , up 48% from $2.75 just two months earlier. The reported driver is rising demand tied…
14 Apr
Anthropic Releases Claude Mythos Preview with Cybersecurity Capabilities but Withholds Public Access
Anthropic Releases Claude Mythos Preview with Cybersecurity Capabilities but Withholds Public Access
Anthropic has introduced Claude Mythos Preview, its most advanced AI model, improving significantly in reasoning, coding, and cybersecurity. Unlike previous releases, it will not be publicly available. Access is limited to a consortium of tech companies throu…
14 Apr