Backdoored Telnyx PyPI package pushes malware hidden in WAV audio

2026-03-28T07:23:26Zc54ffa809b2534d575e6a3ef2ee7fc16419732ca003fa72f8a1ef635c808faa6
AWSCISACorunaGitHubLangflowPyPIcloud-compromisecredential-theftdata-breachdeveloper-targetingexploitfraudiOS-exploit-frameworkmalwarephishingsanctionssecurity-updatesteganographysupply-chain

What happened

Multiple high-impact security incidents reported: a backdoored Telnyx PyPI package was published that delivers credential‑stealing malware hidden inside a WAV file (supply‑chain/malware). A large campaign used fake Visual Studio Code security alerts in GitHub Discussions to trick developers into downloading malware. CISA warned of active exploitation of a critical Langflow vulnerability (CVE-2026-33017) that allows hijacking AI workflows. Other notable items include an Amazon cloud account breach affecting the European Commission, phishing attacks against TikTok for Business and the Dutch PolO

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c54ffa809b2534d575e6a3ef2ee7fc16419732ca003fa72f8a1ef635c808faa6
Enrichment time
2026-03-28T07:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Backdoored Telnyx PyPI package pushes malware hidden in WAV audio · Baitaphish