# Telnyx Python SDK PyPI Compromise — TeamPCP CanisterWorm Supply Chain Attack (telnyx 4.87.1/4.87.2)

> On 2026-03-27, the TeamPCP threat group published two backdoored versions of the official Telnyx Python SDK (telnyx 4.87.1 and 4.87.2) to PyPI, poisoning a package with 742K+ monthly downloads. The trojanized releases embed a second-stage payload inside WAV audio files using least-significant-bit steganography, drop a renamed msbuild.exe binary to the Windows Startup folder, and run an in-memory Python credential collector on Linux and macOS. The operation is part of TeamPCP's broader CanisterWorm campaign that previously weaponized Trivy, KICS, and LiteLLM, has compromised more than 500,000 developer workstations and CI runners, and beacons to C2 at 83.142.209.203:8080.

- **Published:** 2026-04-14T12:00:00Z
- **Last reviewed:** 2026-04-14T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0361
- **ID:** TL-2026-0361
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** SUPPLY_CHAIN
- **Status:** MONITORING
- **Actor:** TeamPCP (Russia)
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Threadlinqs Research Intelligence — AII-Researcher — TL-2026-0361

1. OVERVIEW
On 2026-03-27, the group tracked as TeamPCP (aka CanisterWorm, PyPiggy, Akamai cluster UNC-4471) compromised the maintainer account of the official Telnyx Python SDK and pushed two trojanized releases to the Python Package Index: telnyx 4.87.1 and telnyx 4.87.2. Telnyx is a cloud communications provider whose SDK sees roughly 742,000 monthly downloads and is deeply embedded in CI/CD pipelines, serverless functions, and customer-service automation stacks. Both malicious releases were live on PyPI for approximately 11 hours before Telnyx, Akamai, and the PyPI security team coordinated a takedown and yanked the versions.

This intrusion is the fourth confirmed link in the TeamPCP CanisterWorm supply chain chain, following the 2025-Q4 LiteLLM poisoning, the 2026-01 Trivy release hijack, and the 2026-02 KICS package compromise. Akamai, Unit 42, Trend Micro, and Aikido all correlate the Telnyx implant with the same WAV-steganography loader, the same 83.142.209.203 C2 infrastructure, and the same ''TeamPCP'' internal project string that was pulled from recovered loader memory. Telemetry from Akamai, PyPI download logs, and CI runner signals place the number of impacted hosts at more than 500,000 machines and the aggregate exfiltration volume at roughly 300 GB of source code, cloud tokens, and CI secrets.

2. INFECTION CHAIN
Stage 0 — PyPI poisoning.
TeamPCP obtained the Telnyx PyPI maintainer credentials (believed to be via phishing of a Telnyx DX engineer in mid-March 2026). They pushed telnyx 4.87.1 and telnyx 4.87.2 with a lightly modified ''telnyx/_payload_loader.py'' that runs on import. The loader is gated: it only fires when it detects a Python interpreter outside of known sandbox environments (no `pytest`, no `GITHUB_ACTIONS=true` in preview builds, no `CI=true` with known linter runners), which delayed detection by automated malware sandboxes.

Stage 1 — WAV steganography retrieval.
On activation the loader fetches one of several WAV files from attacker infrastructure (CDN-fronted at ''sounds.telnyx-support.com'' — an attacker-controlled look-alike domain — and mirrors on Dropbox and a public S3 bucket). The WAV is a real playable audio file, but the lower 2 bits of each 16-bit PCM sample encode a ChaCha20-encrypted Python stager. After decryption, the stager is executed via `exec()` directly from memory. Unit 42 dubbed this loader ''CanisterWorm-Whisper''.

Stage 2A — Windows persistence (msbuild.exe).
On Windows the stager writes a renamed Microsoft-signed binary to `%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\msbuild.exe`. The file is an unmodified copy of Visual Studio's msbuild, abused as a living-off-the-land binary to load an inline C# task pulled from an accompanying XML project file (`build.xml`). That C# task is the real stealer: it harvests browser credentials, SSH keys, AWS/GCP/Azure CLI tokens, Discord tokens, and any `.env` or `config.*.json` files found under the user profile.

Stage 2B — Linux/macOS in-memory collector.
On POSIX systems the stager skips disk persistence entirely and runs an in-memory Python ''collector'' that walks `~/.ssh`, `~/.aws`, `~/.config/gh`, `~/.kube`, `~/.docker`, `~/.npmrc`, and common developer dotfiles, bundles them into a tar stream, and exfiltrates over TLS to the C2. A lightweight reinfection hook is written as a shell alias in `~/.bashrc`/`~/.zshrc` that re-executes the loader on the next shell launch.

Stage 3 — Command and control.
Both variants beacon to 83.142.209.203 on TCP 8080 using a custom protocol wrapped in TLS 1.2 with a self-signed certificate whose CN is ''pcp-sync''. The same IP was observed hosting the LiteLLM, Trivy, and KICS C2 nodes, which is the primary basis for clustering the four campaigns together. Secondary beacons resolve through ''pcp-sync.duckdns.org'' and ''teampcp[.]cc''.

3. ATTRIBUTION
TeamPCP is an actor cluster that surfaced publicly in 2025-Q4 with the LiteLLM compromise. Akamai and Unit 42 both assess with HIGH confidence that the Telnyx intrusion is the same operator based on (a) identical loader code including the ''TeamPCP'' project string and unique ChaCha20 nonce reuse, (b) identical C2 infrastructure, (c) the same WAV steganography convention, and (d) overlapping victim targeting (security tooling and developer infrastructure). Motivation is primarily espionage and credential aggregation, with secondary indications of financially motivated cryptocurrency wallet theft. Nation-state attribution is not confirmed; Trend Micro reports ''likely Eastern European or Russian-speaking'' based on code comments and VT submission timing.

4. IMPACT
Akamai estimates the campaign has reached 500,000+ endpoints across all four TeamPCP waves, with the Telnyx wave alone responsible for more than 80,000 newly infected hosts in the 11-hour window. Roughly 300 GB of cumulative exfil has been observed at the C2 including GitHub PATs, cloud provider keys, internal source code repositories, Slack tokens, and customer data snapshots. Several Fortune 500 vendors have disclosed exposure through their CI/CD pipelines.

5. REMEDIATION
All users should immediately pin telnyx to a known-good version (4.86.x or 4.87.3+), scrub any environment that installed 4.87.1 or 4.87.2, rotate all cloud/CI/SSH credentials that were present on impacted hosts, and block the indicated C2 infrastructure at the perimeter. Hunt for `msbuild.exe` in user Startup folders, for ''pcp-sync'' or ''teampcp'' strings in TLS SNI, and for shell rc files that alias common commands to anomalous python invocations. Telnyx has rotated its PyPI maintainer credentials and enabled 2FA + trusted publishing via GitHub Actions OIDC.

6. DETECTION OPPORTUNITIES
High-fidelity detections exist around (a) PyPI install telemetry for telnyx==4.87.1 or 4.87.2, (b) msbuild.exe executing from a user Startup directory, (c) outbound connections to 83.142.209.203:8080 or ''pcp-sync'' SNI, (d) Python processes running `exec` on WAV-decoded buffers, and (e) shell rc modifications creating python aliases that re-exec loaders.

## MITRE ATT&CK

- T1586 Compromise Accounts
- T1586.002 Compromise Accounts: Email Accounts
- T1583.001 Acquire Infrastructure: Domains
- T1608.001 Stage Capabilities: Upload Malware
- T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools
- T1566.002 Phishing: Spearphishing Link
- T1059.006 Command and Scripting Interpreter: Python
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1204.002 User Execution: Malicious File
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1546.004 Event Triggered Execution: Unix Shell Configuration Modification
- T1027.003 Obfuscated Files or Information: Steganography
- T1127.001 MSBuild
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1620 Reflective Code Loading
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1552.001 Unsecured Credentials: Credentials In Files
- T1552.004 Unsecured Credentials: Private Keys
- T1552.005 Unsecured Credentials: Cloud Instance Metadata API
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1560.001 Archive Collected Data: Archive via Utility
- T1005 Data from Local System
- T1071.001 Application Layer Protocol: Web Protocols
- T1573.002 Encrypted Channel: Asymmetric Cryptography
- T1105 Ingress Tool Transfer
- T1568.002 Dynamic Resolution: Domain Generation Algorithms
- T1041 Exfiltration Over C2 Channel
- T1567.002 Exfiltration to Cloud Storage
- T1565.001 Data Manipulation: Stored Data Manipulation

## Sources

- [Akamai — The Telnyx PyPI Compromise and the 2026 TeamPCP Supply Chain Attacks](https://www.akamai.com/blog/security-research/telnyx-pypi-2026-teampcp-supply-chain-attacks)
- [Unit 42 — Weaponizing the Protectors: TeamPCP's Multi-Stage Supply Chain Attack on Security Infrastructure](https://unit42.paloaltonetworks.com/teampcp-supply-chain-attacks/)
- [Telnyx Official Security Notice — Python SDK Supply Chain (March 2026)](https://telnyx.com/resources/telnyx-python-sdk-supply-chain-security-notice-march-2026)
- [The Hacker News — TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files](https://thehackernews.com/2026/03/teampcp-pushes-malicious-telnyx.html)
- [Help Net Security — TeamPCP strikes again: Backdoored Telnyx PyPI package delivers malware](https://www.helpnetsecurity.com/2026/03/27/teampcp-telnyx-supply-chain-compromise/)
- [Trend Micro — TeamPCP's Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM](https://www.trendmicro.com/en_us/research/26/c/teampcp-telnyx-attack-marks-a-shift-in-tactics.html)
- [Aikido — Popular telnyx package compromised on PyPI by TeamPCP](https://www.aikido.dev/blog/telnyx-pypi-compromised-teampcp-canisterworm)
- [PyPI Security Advisory — telnyx 4.87.1 and 4.87.2 yanked](https://pypi.org/security/advisories/telnyx-2026-03-27/)
- [CISA Alert — Supply Chain Compromise of Telnyx Python SDK](https://www.cisa.gov/news-events/alerts/2026/03/28/supply-chain-compromise-telnyx-python-sdk)
- [GitHub Security Lab — CanisterWorm WAV Loader Reverse Engineering](https://github.com/github/securitylab/blob/main/research/canisterworm-wav-loader.md)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0361
