Story perspectives
Malicious Python Package Compromises Users' Credentials Across Platforms
3/28/2026
1 of 1
Story summary
- TeamPCP compromised the Telnyx Python package by releasing malicious versions 4.87.1 and 4.87.2 on March 27, 2026.
- The Python Package Index (PyPI) releases use audio steganography to conceal credential harvesting within a WAV file.
- The malware targets Windows, Linux, and macOS and exfiltrates sensitive information.
- The Python Package Index (PyPI) project has been quarantined, and users are advised to downgrade to version 4.87.0.
