Threat reportSupply ChainTL-2026-0361

Telnyx Python SDK PyPI Compromise — TeamPCP CanisterWorm Supply Chain Attack (telnyx 4.87.1/4.87.2)

criticalMONITORING

Telnyx Python SDK PyPI Compromise (TL-2026-0361), also tracked as CanisterWorm-Telnyx, is a critical-severity supply-chain compromise scored CVSS 9.8, first published 2026-04-14. It is attributed to TeamPCP (Russia) with high confidence, affects Telnyx telnyx (Python SDK on PyPI), maps to 30 MITRE ATT&CK techniques (T1005, T1027.003, T1041), and is covered by 9 detection rules and 23 indicators of compromise.

CVSS
9.8/10Critical
CVEs
0None referenced
Techniques
30MITRE ATT&CK
Actors
1TeamPCP
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-0361

Threat ID
TL-2026-0361
Also known as
CanisterWorm-Telnyx, Operation Whisper, TeamPCP Wave 4, Telnyx PyPI Poisoning
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
MONITORING
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
TeamPCP
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
technology, telecommunications, financial, healthcare, saas, devops, government
Target regions
North America, Europe, Asia Pacific, South America
Detection rules
9
Indicators of compromise
23

Malware and tooling in Telnyx Python SDK PyPI Compromise

Malware and tooling: CanisterWorm, CanisterWorm-Whisper, Custom TLS 1.2 over TCP/8080 with self-signed cert CN=pcp-sync

How Telnyx Python SDK PyPI Compromise works

On 2026-03-27, the TeamPCP threat group published two backdoored versions of the official Telnyx Python SDK (telnyx 4.87.1 and 4.87.2) to PyPI, poisoning a package with 742K+ monthly downloads. The trojanized releases embed a second-stage payload inside WAV audio files using least-significant-bit steganography, drop a renamed msbuild.exe binary to the Windows Startup folder, and run an in-memory Python credential collector on Linux and macOS. The operation is part of TeamPCP's broader CanisterWorm campaign that previously weaponized Trivy, KICS, and LiteLLM, has compromised more than 500,000 developer workstations and CI runners, and beacons to C2 at 83.142.209.203:8080.

Threadlinqs Research Intelligence — AII-Researcher — TL-2026-0361

1. OVERVIEW On 2026-03-27, the group tracked as TeamPCP (aka CanisterWorm, PyPiggy, Akamai cluster UNC-4471) compromised the maintainer account of the official Telnyx Python SDK and pushed two trojanized releases to the Python Package Index: telnyx 4.87.1 and telnyx 4.87.2. Telnyx is a cloud communications provider whose SDK sees roughly 742,000 monthly downloads and is deeply embedded in CI/CD pipelines, serverless functions, and customer-service automation stacks. Both malicious releases were live on PyPI for approximately 11 hours before Telnyx, Akamai, and the PyPI security team coordinated a takedown and yanked the versions.

This intrusion is the fourth confirmed link in the TeamPCP CanisterWorm supply chain chain, following the 2025-Q4 LiteLLM poisoning, the 2026-01 Trivy release hijack, and the 2026-02 KICS package compromise. Akamai, Unit 42, Trend Micro, and Aikido all correlate the Telnyx implant with the same WAV-steganography loader, the same 83.142.209.203 C2 infrastructure, and the same ''TeamPCP'' internal project string that was pulled from recovered loader memory. Telemetry from Akamai, PyPI download logs, and CI runner signals place the number of impacted hosts at more than 500,000 machines and the aggregate exfiltration volume at roughly 300 GB of source code, cloud tokens, and CI secrets.

2. INFECTION CHAIN Stage 0 — PyPI poisoning. TeamPCP obtained the Telnyx PyPI maintainer credentials (believed to be via phishing of a Telnyx DX engineer in mid-March 2026). They pushed telnyx 4.87.1 and telnyx 4.87.2 with a lightly modified ''telnyx/_payload_loader.py'' that runs on import. The loader is gated: it only fires when it detects a Python interpreter outside of known sandbox environments (no `pytest`, no `GITHUB_ACTIONS=true` in preview builds, no `CI=true` with known linter runners), which delayed detection by automated malware sandboxes.

Stage 1 — WAV steganography retrieval. On activation the loader fetches one of several WAV files from attacker infrastructure (CDN-fronted at ''sounds.telnyx-support.com'' — an attacker-controlled look-alike domain — and mirrors on Dropbox and a public S3 bucket). The WAV is a real playable audio file, but the lower 2 bits of each 16-bit PCM sample encode a ChaCha20-encrypted Python stager. After decryption, the stager is executed via `exec()` directly from memory. Unit 42 dubbed this loader ''CanisterWorm-Whisper''.

Stage 2A — Windows persistence (msbuild.exe). On Windows the stager writes a renamed Microsoft-signed binary to `%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\msbuild.exe`. The file is an unmodified copy of Visual Studio's msbuild, abused as a living-off-the-land binary to load an inline C# task pulled from an accompanying XML project file (`build.xml`). That C# task is the real stealer: it harvests browser credentials, SSH keys, AWS/GCP/Azure CLI tokens, Discord tokens, and any `.env` or `config.*.json` files found under the user profile.

Stage 2B — Linux/macOS in-memory collector. On POSIX systems the stager skips disk persistence entirely and runs an in-memory Python ''collector'' that walks `~/.ssh`, `~/.aws`, `~/.config/gh`, `~/.kube`, `~/.docker`, `~/.npmrc`, and common developer dotfiles, bundles them into a tar stream, and exfiltrates over TLS to the C2. A lightweight reinfection hook is written as a shell alias in `~/.bashrc`/`~/.zshrc` that re-executes the loader on the next shell launch.

Stage 3 — Command and control. Both variants beacon to 83.142.209.203 on TCP 8080 using a custom protocol wrapped in TLS 1.2 with a self-signed certificate whose CN is ''pcp-sync''. The same IP was observed hosting the LiteLLM, Trivy, and KICS C2 nodes, which is the primary basis for clustering the four campaigns together. Secondary beacons resolve through ''pcp-sync.duckdns.org'' and ''teampcp[.]cc''.

3. ATTRIBUTION TeamPCP is an actor cluster that surfaced publicly in 2025-Q4 with the LiteLLM compromise. Akamai and Unit 42 both assess with HIGH confidence that the Telnyx intrusion is the same operator based on (a) identical loader code including the ''TeamPCP'' project string and unique ChaCha20 nonce reuse, (b) identical C2 infrastructure, (c) the same WAV steganography convention, and (d) overlapping victim targeting (security tooling and developer infrastructure). Motivation is primarily espionage and credential aggregation, with secondary indications of financially motivated cryptocurrency wallet theft. Nation-state attribution is not confirmed; Trend Micro reports ''likely Eastern European or Russian-speaking'' based on code comments and VT submission timing.

4. IMPACT Akamai estimates the campaign has reached 500,000+ endpoints across all four TeamPCP waves, with the Telnyx wave alone responsible for more than 80,000 newly infected hosts in the 11-hour window. Roughly 300 GB of cumulative exfil has been observed at the C2 including GitHub PATs, cloud provider keys, internal source code repositories, Slack tokens, and customer data snapshots. Several Fortune 500 vendors have disclosed exposure through their CI/CD pipelines.

5. REMEDIATION All users should immediately pin telnyx to a known-good version (4.86.x or 4.87.3+), scrub any environment that installed 4.87.1 or 4.87.2, rotate all cloud/CI/SSH credentials that were present on impacted hosts, and block the indicated C2 infrastructure at the perimeter. Hunt for `msbuild.exe` in user Startup folders, for ''pcp-sync'' or ''teampcp'' strings in TLS SNI, and for shell rc files that alias common commands to anomalous python invocations. Telnyx has rotated its PyPI maintainer credentials and enabled 2FA + trusted publishing via GitHub Actions OIDC.

6. DETECTION OPPORTUNITIES High-fidelity detections exist around (a) PyPI install telemetry for telnyx==4.87.1 or 4.87.2, (b) msbuild.exe executing from a user Startup directory, (c) outbound connections to 83.142.209.203:8080 or ''pcp-sync'' SNI, (d) Python processes running `exec` on WAV-decoded buffers, and (e) shell rc modifications creating python aliases that re-exec loaders.

MITRE ATT&CK techniques used in TL-2026-0361

Collection

T1005 Data from Local System; T1560.001 Archive Collected Data: Archive via Utility

Defense Evasion

T1027.003 Obfuscated Files or Information: Steganography; T1127.001 MSBuild; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567.002 Exfiltration to Cloud Storage

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1573.002 Encrypted Channel: Asymmetric Cryptography

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Initial Access

T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools; T1566.002 Phishing: Spearphishing Link

Persistence

T1546.004 Event Triggered Execution: Unix Shell Configuration Modification; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Credential Access

T1552.001 Unsecured Credentials: Credentials In Files; T1552.004 Unsecured Credentials: Private Keys; T1552.005 Unsecured Credentials: Cloud Instance Metadata API; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Impact

T1565.001 Data Manipulation: Stored Data Manipulation

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1586 Compromise Accounts; T1586.002 Compromise Accounts: Email Accounts; T1608.001 Stage Capabilities: Upload Malware

Affected products and versions in Telnyx Python SDK PyPI Compromise

  • Telnyx — telnyx (Python SDK on PyPI)
    Vulnerable versions: 4.87.1; 4.87.2
    Fixed in: 4.87.3; 4.86.x (unaffected)
  • Python Software Foundation — PyPI package registry
    Vulnerable versions: N/A — registry trust model
    Fixed in: Trusted Publishing / OIDC enabled projects

Remediation for Telnyx Python SDK PyPI Compromise

Patches

  • Upgrade to telnyx 4.87.3 (clean release published 2026-03-27 18:40 UTC after takedown)
  • Apply Telnyx Security Notice recommended version pins

Immediate actions

  • Pin telnyx to 4.86.x or >=4.87.3; uninstall 4.87.1 and 4.87.2 immediately
  • Block outbound traffic to 83.142.209.203/32 and DNS for pcp-sync.duckdns.org and teampcp.cc
  • Hunt for msbuild.exe in %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ on all Windows developer machines
  • Rotate all cloud credentials, GitHub PATs, SSH keys, and CI secrets from any host that installed 4.87.1 or 4.87.2
  • Inspect ~/.bashrc, ~/.zshrc and shell rc files on Linux/macOS for python re-exec aliases
  • Review PyPI mirror logs and internal artifact proxies for telnyx==4.87.1 or 4.87.2 downloads

Workarounds

  • Temporarily switch to the Telnyx REST API via direct HTTPS calls if SDK upgrade is blocked
  • Air-gap CI runners that built against 4.87.1/4.87.2 pending full re-image

Longer-term hardening

  • Enforce PyPI trusted publishing (OIDC) for all first-party and vendored packages
  • Require 2FA and hardware keys for all package registry maintainer accounts
  • Deploy a package firewall (e.g. Cloudsmith, JFrog Curation) to block unreviewed PyPI versions
  • Implement SBOM generation and drift detection in CI/CD pipelines
  • Add egress filtering on developer workstations and CI runners to a deny-by-default posture
  • Build detection content for WAV/image steganography loaders and exec-from-memory Python patterns

Weaknesses (CWE) in Telnyx Python SDK PyPI Compromise

CWE-506, CWE-494, CWE-1357, CWE-829

Timeline of Telnyx Python SDK PyPI Compromise

  • TeamPCP surfaces publicly with the LiteLLM PyPI poisoning; Akamai first attributes the cluster and publishes the CanisterWorm naming.
  • TeamPCP compromises the Trivy release pipeline, pushing a trojanized scanner binary — same WAV loader convention observed.
  • KICS PyPI package compromised by TeamPCP using reused ChaCha20 nonce and identical C2 at 83.142.209.203:8080.
  • Spearphishing campaign targets Telnyx developer experience engineers; maintainer credentials for the PyPI telnyx project are stolen.
  • Telnyx posts official security notice; Akamai, Aikido, Help Net Security, and The Hacker News publish coverage.
  • PyPI security team yanks 4.87.1 and 4.87.2 at 18:22 UTC after Telnyx and Akamai jointly report; Telnyx publishes 4.87.3 clean release at 18:40 UTC.
  • Akamai SOC observes anomalous DNS to sounds.telnyx-support.com and ties telemetry back to a specific pip install telemetry bucket.
  • TeamPCP publishes telnyx 4.87.1 at 07:12 UTC and telnyx 4.87.2 at 08:04 UTC to PyPI.
  • Trend Micro publishes tactical analysis linking Telnyx wave to the broader TeamPCP CanisterWorm cluster.
  • CISA issues alert on the Telnyx supply chain compromise and recommends credential rotation for all impacted hosts.
  • GitHub Security Lab releases full reverse engineering of the CanisterWorm WAV loader including decryption keys.
  • Palo Alto Unit 42 publishes multi-campaign analysis confirming 500K+ impacted hosts and ~300GB cumulative exfil.
  • BeaconBeagle catalogs 83.142.209.203:8080 as active C2 with self-signed cert CN=pcp-sync, confirming links to LiteLLM and Trivy incidents.
  • As of 2026-05-29, the specific Telnyx PyPI poisoning is contained — versions 4.87.1/4.87.2 were yanked within ~11 hours and clean 4.87.3 shipped. But actor TeamPCP/UNC6780 remains highly active, with a GitHub internal-repo breach (May 18-20) and TanStack npm wave (May 11) extending the same CanisterWorm/Mini Shai-Hulud campaign.

Sources cited for Telnyx Python SDK PyPI Compromise

Detection coverage for TL-2026-0361

As of 2026-04-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0361 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats