TeamPCP strikes again: Backdoored Telnyx PyPI package delivers malware

2026-03-27T14:51:54Z239b7233fd3cf2c414dd65d6df78a65a40ac7b6a9414be1e3fc6a4b3511ff4de
BPFDoorCISAGitGuardianGitHubLangflowOpenAIPyPIRCERedLineTailsTeamPCPTorTrivybackdoorbug-bountycredential-leakdata-breachdata-privacydetection-toolinfostealerknown-exploited-vulnerabilitiesmalwaresecrets-managementsupply-chain

What happened

Multiple high-impact supply-chain and exploitation events were reported. Endor Labs attributes a new TeamPCP campaign to backdooring the Telnyx PyPI SDK (malicious versions published as 4.87.1 and 4.87.2) that delivers malware. CISA added CVE-2026-33017 (Langflow code-injection / RCE) and CVE-2026-33634 (embedded malicious code in Aqua Trivy) to its Known Exploited Vulnerabilities catalog, forcing US federal remediation with near-term deadlines. Other notable items: AFC Ajax disclosed an app/website compromise exposing emails and limited PII; GitGuardian’s 2026 report documents massive secrets

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
239b7233fd3cf2c414dd65d6df78a65a40ac7b6a9414be1e3fc6a4b3511ff4de
Enrichment time
2026-03-27T14:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.