Major compromise of telnyx PyPI library could put millions of users at risk


  • JFrog reports that Telnyx PyPI package was poisoned with malware by TeamPCP
  • Malicious update delivered hidden .wav payload that deployed information theft and persistence mechanisms
  • Users are advised to downgrade, block C2 communication, rotate credentials, and check for persistence.

Telnyx, a popular PyPI package offering real-time communication features, was recently poisoned and used to deliver malware to its users, experts have warned.

A report from security researchers JFrog, along with other independent security experts, shows how, as a cloud platform that allows developers to add real-time communications capabilities to applications, such as voice and messaging, Telnyx provides APIs and tools to create solutions such as calling systems and SMS-based services.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top