INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Telnyx joins LiteLLM in PyPI package poisoning tied to breach

| 2026-03-30 17:42 CRITICAL LOW DATA BREACH SUPPLY CHAIN
Executive Summary
AI-generated
A cybercrime crew linked to the Trivy supply-chain attack, known as TeamPCP, has compromised a legitimate software package on PyPI, replacing current versions with malicious releases containing infostealer and persistence mechanisms. The malicious Telnyx package was discovered by Ox Security, which warned that it may have affected developers who installed the Python SDK version 4.87.1 or 4.87.2 before it was removed. As a result, anyone using these versions should treat their environment as compromised and rotate exposed credentials. Meanwhile, an alleged RedLine operator, Hambardzum Minasyan, has been extradited to the US to face charges related to his involvement in the development of the prolific infostealer operation, which is believed to be linked to TeamPCP.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
LAPSUS$LAPSUS$
Target & Sectors
NORTH_AMERICA NORTH_AMERICA technologytechnology
Incident Timeline
‎2026/03/30
TeamPCP compromised the PyPI distribution of Telnyx's Python SDK, replacing current package versions with malicious releases loaded with a multi-stage infostealer and persistence mechanisms.
financial $10 bounty
infrastructure 4.87.1
infrastructure 4.87.2
infrastructure 2.66
threat_actor LAPSUS$
data_breach 2.66 GB
infrastructure 34,000 downloads
Tactical Metrics
Metrics
financial
10,000,000
Bounty
Metrics
infrastructure
​4.87.1
Software Version
Metrics
infrastructure
​4.87.2
Software Version
Metrics
infrastructure
​2.66
Software Version
Metrics
data_breach
3
Gb
Metrics
infrastructure
34,000
Downloads
Intelligence Sources
The Register - Cybercrime 2026-03-30