GHSA-955r-262c-33jc
## Summary On March 27, 2026, a threat actor used compromised PyPI credentials to publish malicious versions 4.87.1 and 4.87.2 of the `telnyx` Python package directly to PyPI. These versions contain credential-stealing malware and were not published through the legitimate GitHub release pipeline. ## Exposure Window | Version | Published (UTC) | Quarantined (UTC) | Exposure | |---------|-----------------|-------------------|----------| | 4.87.1 (broken) | 2026-03-27 03:51 | 2026-03-27 10:13 | 6h 22m | | 4.87.2 (functional) | 2026-03-27 04:07 | 2026-03-27 10:13 | 6h 6m | **Both versions were quarantined by PyPI at 2026-03-27 10:13 UTC.** **Note:** Version 4.87.1 contained a typo that prevented the malware from executing. Only 4.87.2 was fully functional. ## Who Is Affected You may be affected if: - You installed or upgraded the `telnyx` Python package between 03:51 UTC and 10:13 UTC on March 27, 2026 - You ran `pip install telnyx` without pinning a version and received 4.87.1 or 4.87.2 - A dependency in your project pulled in `telnyx` as a transitive, unpinned dependency You are NOT affected if: - You pinned to version 4.87.0 or earlier - You installed before March 27, 2026 and did not upgrade - You built from GitHub source (malicious code was never committed to the repository) ## Attack Details ### Root Cause The attacker obtained the PyPI API token and uploaded malicious packages directly to PyPI, bypassing the GitHub release pipeline entirely. No malicious commits exist in the GitHub repository. ### Malicious Behavior The malware is injected into `telnyx/_client.py` (74 additional lines) and executes on `import telnyx`: **Linux/macOS:** 1. Spawns detached subprocess to survive parent exit 2. Downloads payload hidden inside WAV audio file (steganography) from C2 3. Harvests credentials: SSH keys, AWS/GCP/Azure creds, Kubernetes tokens, Docker configs, .env files, database credentials, crypto wallets 4. If Kubernetes access found, deploys privileged po
Properties
- ghsa_id
- GHSA-955r-262c-33jc
- severity
- critical
- summary
- Telnyx has malicious code in PyPI versions 4.87.1 and 4.87.2
- cve_id
- GHSA-955r-262c-33jc
- is_ghsa_only
- true
- ghsa_published
- 2026-03-30T19:15:30Z
- source_url
- https://github.com/advisories/GHSA-955r-262c-33jc
- ghsa_updated
- 2026-03-30T19:15:31Z
Related Entities (3)
HAS_WEAKNESS (1)
REPORTED_BY (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph