TeamPCP strikes again: Backdoored Telnyx PyPI package delivers malware
2026-03-27T14:51:54Z•239b7233fd3cf2c414dd65d6df78a65a40ac7b6a9414be1e3fc6a4b3511ff4de
BPFDoorCISAGitGuardianGitHubLangflowOpenAIPyPIRCERedLineTailsTeamPCPTorTrivybackdoorbug-bountycredential-leakdata-breachdata-privacydetection-toolinfostealerknown-exploited-vulnerabilitiesmalwaresecrets-managementsupply-chain
What happened
Multiple high-impact supply-chain and exploitation events were reported. Endor Labs attributes a new TeamPCP campaign to backdooring the Telnyx PyPI SDK (malicious versions published as 4.87.1 and 4.87.2) that delivers malware. CISA added CVE-2026-33017 (Langflow code-injection / RCE) and CVE-2026-33634 (embedded malicious code in Aqua Trivy) to its Known Exploited Vulnerabilities catalog, forcing US federal remediation with near-term deadlines. Other notable items: AFC Ajax disclosed an app/website compromise exposing emails and limited PII; GitGuardian’s 2026 report documents massive secrets
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 239b7233fd3cf2c414dd65d6df78a65a40ac7b6a9414be1e3fc6a4b3511ff4de
- Enrichment time
- 2026-03-27T14:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.