Socket Research Team uncovered a supply chain attack on the official Telnyx Python SDK on PyPI. Threat actor group TeamPCP uploaded malicious versions 4.87.1 and 4.87.2 containing credential-stealing malware injected into the core client module. The attack uses a three-stage chain: audio steganography to deliver a second-stage

20m read timeFrom socket.dev
Post cover image
Table of contents
Technical Analysis #Outlook and Recommendations #Indicators of Compromise (IOCs) #

Sort: