INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Telnyx joins LiteLLM in PyPI package poisoning tied to breach
| 2026-03-30 17:42 CRITICAL LOW DATA BREACH SUPPLY CHAIN
Executive Summary
AI-generated
A cybercrime crew linked to the Trivy supply-chain attack, known as TeamPCP, has compromised a legitimate software package on PyPI, replacing current versions with malicious releases containing infostealer and persistence mechanisms. The malicious Telnyx package was discovered by Ox Security, which warned that it may have affected developers who installed the Python SDK version 4.87.1 or 4.87.2 before it was removed. As a result, anyone using these versions should treat their environment as compromised and rotate exposed credentials. Meanwhile, an alleged RedLine operator, Hambardzum Minasyan, has been extradited to the US to face charges related to his involvement in the development of the prolific infostealer operation, which is believed to be linked to TeamPCP.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
LAPSUS$LAPSUS$
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
technologytechnology
Incident Timeline
2026/03/30
TeamPCP compromised the PyPI distribution of Telnyx's Python SDK, replacing current package versions with malicious releases loaded with a multi-stage infostealer and persistence mechanisms.
Click on any entity below to view its context and source!
financial
$10 bounty
Last year, the US government offered a $10 million bounty for information on Rudometov and his co-conspirators.
infrastructure
4.87.1
Those worried they might be affected should check their installed Telnyx version — if you're running 4.87.1 or 4.87.2, Telnyx recommends treating the host as compromised and rotating any exposed credentials.
infrastructure
4.87.2
Those worried they might be affected should check their installed Telnyx version — if you're running 4.87.1 or 4.87.2, Telnyx recommends treating the host as compromised and rotating any exposed credentials.
infrastructure
2.66
LAPSUS$ spills alleged AstraZeneca data
The cybercriminals behind the LAPSUS$ threat group have released 2.66 GB of data allegedly stolen from drug maker AstraZeneca, and threat watchers say it could become one of the more serious healthcare cybe…
threat_actor
LAPSUS$
LAPSUS$ spills alleged AstraZeneca data
The cybercriminals behind the LAPSUS$ threat group have released 2.66 GB of data allegedly stolen from drug maker AstraZeneca, and threat watchers say it could become one of the more serious healthcare cybe…
According to SOCRadar, LAPSUS$
claimed
to have hit AstraZeneca recently, making off with what they claim are internal code repositories, access-related data, cloud and infrastructure references, and employee records - data which could be devastat…
LAPSUS$ released the full dataset over the weekend, SOCRadar reported.
data_breach
2.66 GB
LAPSUS$ spills alleged AstraZeneca data
The cybercriminals behind the LAPSUS$ threat group have released 2.66 GB of data allegedly stolen from drug maker AstraZeneca, and threat watchers say it could become one of the more serious healthcare cybe…
infrastructure
34,000 downloads
Telnyx sees more than 34,000 downloads a week on PyPI, Ox noted, so it's possible quite a few developers and services pulled one of the malicious releases before they were removed.
Tactical Metrics
Metrics
financial
10,000,000
Bounty
Click for context!
Last year, the US government offered a $10 million bounty for information on Rudometov and his co-conspirators.
Metrics
infrastructure
4.87.1
Software Version
Those worried they might be affected should check their installed Telnyx version — if you're running 4.87.1 or 4.87.2, Telnyx recommends treating the host as compromised and rotating any exposed credentials.
Metrics
infrastructure
4.87.2
Software Version
Those worried they might be affected should check their installed Telnyx version — if you're running 4.87.1 or 4.87.2, Telnyx recommends treating the host as compromised and rotating any exposed credentials.
Metrics
infrastructure
2.66
Software Version
LAPSUS$ spills alleged AstraZeneca data
The cybercriminals behind the LAPSUS$ threat group have released 2.66 GB of data allegedly stolen from drug maker AstraZeneca, and threat watchers say it could become one of the more serious healthcare cybe…
Metrics
data_breach
3
Gb
LAPSUS$ spills alleged AstraZeneca data
The cybercriminals behind the LAPSUS$ threat group have released 2.66 GB of data allegedly stolen from drug maker AstraZeneca, and threat watchers say it could become one of the more serious healthcare cybe…
Metrics
infrastructure
34,000
Downloads
Telnyx sees more than 34,000 downloads a week on PyPI, Ox noted, so it's possible quite a few developers and services pulled one of the malicious releases before they were removed.
Intelligence Sources
The Register - Cybercrime
2026-03-30
Telnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach
The Register - Cybercrime
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:50
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
RedLine
entity
5x
timeline
Temporal Reference
2024
date
3x
infrastructure
Software Version
4.87.1
version
2x
source region
Origin Country
United States
country
2x
target region
Target Country
United States
country
2x
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
Contextual Telemetry
Context Block
8 METRICS
financial
Bounty
10,000,000
bounty
tactic
Cyber Operation Type
Phishing
tactic
threat actor
APT Group
LAPSUS$
actor
data breach
Gb
3
gb
attribution
Attributing Entity
ORNL Center for
authority
general metric
Resource Utilization
95
resource utilization
general metric
Gpus
1,920
gpus
infrastructure
Downloads
34,000
downloads
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.