Telnyx Python SDK hides credential stealer in WAV-file steganography
TeamPCP published malicious telnyx 4.87.1 and 4.87.2 to PyPI on 27 March 2026 (~670k monthly downloads). Trojanised _client.py downloads steganographic payloads disguised as .wav files over plaintext HTTP, extracts the credential stealer, and persists. Windows variant drops msbuild.exe to the Startup folder; Linux variant uses a user-level systemd service. AES-256-CBC + RSA-4096 envelope for exfil.
Versions named here: 4.87.1, 4.87.2