Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
2026-03-28T13:23:27Z•72e362e2c9f8a6a8c32d89876736992275cf72aacaa40243b820a87ed36269df
AWSCISACVE-2026-33017GitHubLangflowPyPIWAVactive-exploitationcloud-breachcredential-theftdeveloper-targetingmalwarephishingsteganographysupply-chain
What happened
Multiple active threats and high-risk incidents reported: a Telnyx PyPI package was backdoored to deliver credential‑stealing malware hidden inside a WAV file (supply‑chain compromise), and a large campaign used fake VS Code alerts in GitHub Discussions to trick developers into downloading malware. CISA warns of active exploitation of a critical Langflow vulnerability (CVE-2026-33017) used to hijack AI workflows. Separately, the European Commission is investigating an Amazon cloud account breach, and multiple phishing campaigns (including attacks on TikTok for Business and Dutch police) and iO
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 72e362e2c9f8a6a8c32d89876736992275cf72aacaa40243b820a87ed36269df
- Enrichment time
- 2026-03-28T13:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.