Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
2026-03-28T01:23:29Z•baaa5f4f615f9a0f080cb6f7a69e6560f90c0367e9c7728322187046a305190d
AWSCVE-2026-33017CorunaGitHubLangflowPyPIWAVactively-exploitedcloud-compromisecredential-theftdata-marketplacedeveloper-targetingiOS-exploitmalwarephishingsanctionssecurity-patchsocial-engineeringsteganographysupply-chain
What happened
Multiple high-risk supply-chain and active-exploitation incidents were reported: a Telnyx PyPI package was backdoored to deliver credential-stealing malware hidden inside a WAV file (PyPI supply-chain compromise and steganographic payload), and a large GitHub campaign used fake VS Code alerts in Discussions to trick developers into downloading malware. The European Commission is investigating an AWS/cloud account compromise, and CISA warns that CVE-2026-33017 (Langflow) is a critical, actively exploited vulnerability used to hijack AI workflows. Additional notable items include targeted TikTok
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- baaa5f4f615f9a0f080cb6f7a69e6560f90c0367e9c7728322187046a305190d
- Enrichment time
- 2026-03-28T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.