Backdoored Telnyx PyPI package pushes malware hidden in WAV audio

2026-03-28T01:23:29Zbaaa5f4f615f9a0f080cb6f7a69e6560f90c0367e9c7728322187046a305190d
AWSCVE-2026-33017CorunaGitHubLangflowPyPIWAVactively-exploitedcloud-compromisecredential-theftdata-marketplacedeveloper-targetingiOS-exploitmalwarephishingsanctionssecurity-patchsocial-engineeringsteganographysupply-chain

What happened

Multiple high-risk supply-chain and active-exploitation incidents were reported: a Telnyx PyPI package was backdoored to deliver credential-stealing malware hidden inside a WAV file (PyPI supply-chain compromise and steganographic payload), and a large GitHub campaign used fake VS Code alerts in Discussions to trick developers into downloading malware. The European Commission is investigating an AWS/cloud account compromise, and CISA warns that CVE-2026-33017 (Langflow) is a critical, actively exploited vulnerability used to hijack AI workflows. Additional notable items include targeted TikTok

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
baaa5f4f615f9a0f080cb6f7a69e6560f90c0367e9c7728322187046a305190d
Enrichment time
2026-03-28T01:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.