• About
  • Advertise
  • Privacy & Policy
  • Contact
Vidianews
  • Home
  • Entertainment
    • All
    • Gaming
    • Movie
    microsoft’s-search-assistant-can-now-use-multiple-ai-models-simultaneously

    Microsoft’s Search Assistant can now use multiple AI models simultaneously

    brooks-nader-reportedly-dating-after-high-public-links

    Brooks Nader Reportedly Dating After High-Public Links

    taylor-swift-avoids-awkward-altercation-with-john-mayer

    Taylor Swift avoids awkward altercation with John Mayer

    tiger-woods-wouldn’t-hire-a-driver-for-privacy-reasons

    Tiger Woods wouldn’t hire a driver for privacy reasons

    mma-fighter-maycee-barber-says-she-looked-dead-after-crushing-loss

    MMA Fighter Maycee Barber Says She Looked Dead After Crushing Loss

    batman-director-andy-muschetti-addresses-casting-fans-for-the-dark-knight-in-james-gunn’s-live-action-dc-universe

    Batman Director Andy Muschetti Addresses Casting Fans for The Dark Knight in James Gunn’s Live-Action DC Universe

  • Sports
  • Tech
    • All
    • Gadget
    • Startup
    major-compromise-of-telnyx-pypi-library-could-put-millions-of-users-at-risk

    Major compromise of telnyx PyPI library could put millions of users at risk

    mullvad-browser

    Mullvad Browser

    how-we-test-cordless-vacuums

    How We Test Cordless Vacuums

    Best LED Masks of 2026, Cleared by the FDA

    filter-your-entry-with-the-best-video-doorbell-cameras

    Filter your entry with the best video doorbell cameras

    the-pixel-10a-doesn’t-have-a-camera-bump,-and-that’s-great-|-techcrunch

    The Pixel 10a doesn’t have a camera bump, and that’s great | TechCrunch

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Lifestyle
    • All
    • Faith
    • Health
    • Travel
    review:-catgill-farm-glamping,-bolton-abbey,-united-kingdom

    Review: Catgill Farm Glamping, Bolton Abbey, United Kingdom

    everlywell-and-jona-partner-to-expand-access-to-gut-microbiome-testing-–-medcity-news

    Everlywell and Jona partner to expand access to gut microbiome testing – MedCity News

    do-you-want-god-or-just-his-answer?

    Do you want God or just His answer?

    the-best-way-to-exfoliate-for-smooth,-glowing-skin-(without-overdoing-it)

    The Best Way to Exfoliate for Smooth, Glowing Skin (Without Overdoing it)

    how-to-keep-your-home-comfortable-and-pest-free-all-year-round-|-live-better

    How To Keep Your Home Comfortable And Pest-Free All Year Round | Live Better

    5-powerful-ways-god-heals-you-after-a-job-loss

    5 Powerful Ways God Heals You After a Job Loss

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • News
    • All
    • Business
    • Science

    Russian tanker approaches Cuba, Trump de facto softens blockade rhetoric

    trump-reverses-cuba-oil-blockade,-says-he-has-‘no-problem’-with-russian-tanker-delivering-fuel

    Trump reverses Cuba oil blockade, says he has ‘no problem’ with Russian tanker delivering fuel

    trump-says-his-‘preference’-would-be-to-‘take-oil-from-iran’

    Trump says his ‘preference’ would be to ‘take oil from Iran’

    fuel-tax-halved,-free-public-transport-offered-as-war-drives-up-prices-in-australia

    Fuel tax halved, free public transport offered as war drives up prices in Australia

    netanyahu-says-latin-patriarch-will-have-full-access-to-jerusalem-holy-site

    Netanyahu says Latin Patriarch will have full access to Jerusalem holy site

    Thieves steal paintings by Renoir, Cézanne and Matisse in three-minute Italian heist

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Business
  • Politics
  • World
  • Review

    Best Gaming Cryptos and Metaverse for 2022

    Apple’s Mac Pro desktop with M2 Ultra chipset is discontinued almost three years after launch

    Top 5 blockchains for 2022: Ethereum, Avalanche, Polygon, more

    Best DeFi cryptos for 2022: Aave, Balancer, PancakeSwap, more

    Best ways to exchange cryptocurrencies for 2022: Bitcoin, Dash, Litecoin, etc.

    Apple reportedly opens Siri to Gemini, Claude and other third-party AI assistants with iOS 27

No Result
View All Result
  • Home
  • Entertainment
    • All
    • Gaming
    • Movie
    microsoft’s-search-assistant-can-now-use-multiple-ai-models-simultaneously

    Microsoft’s Search Assistant can now use multiple AI models simultaneously

    brooks-nader-reportedly-dating-after-high-public-links

    Brooks Nader Reportedly Dating After High-Public Links

    taylor-swift-avoids-awkward-altercation-with-john-mayer

    Taylor Swift avoids awkward altercation with John Mayer

    tiger-woods-wouldn’t-hire-a-driver-for-privacy-reasons

    Tiger Woods wouldn’t hire a driver for privacy reasons

    mma-fighter-maycee-barber-says-she-looked-dead-after-crushing-loss

    MMA Fighter Maycee Barber Says She Looked Dead After Crushing Loss

    batman-director-andy-muschetti-addresses-casting-fans-for-the-dark-knight-in-james-gunn’s-live-action-dc-universe

    Batman Director Andy Muschetti Addresses Casting Fans for The Dark Knight in James Gunn’s Live-Action DC Universe

  • Sports
  • Tech
    • All
    • Gadget
    • Startup
    major-compromise-of-telnyx-pypi-library-could-put-millions-of-users-at-risk

    Major compromise of telnyx PyPI library could put millions of users at risk

    mullvad-browser

    Mullvad Browser

    how-we-test-cordless-vacuums

    How We Test Cordless Vacuums

    Best LED Masks of 2026, Cleared by the FDA

    filter-your-entry-with-the-best-video-doorbell-cameras

    Filter your entry with the best video doorbell cameras

    the-pixel-10a-doesn’t-have-a-camera-bump,-and-that’s-great-|-techcrunch

    The Pixel 10a doesn’t have a camera bump, and that’s great | TechCrunch

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Lifestyle
    • All
    • Faith
    • Health
    • Travel
    review:-catgill-farm-glamping,-bolton-abbey,-united-kingdom

    Review: Catgill Farm Glamping, Bolton Abbey, United Kingdom

    everlywell-and-jona-partner-to-expand-access-to-gut-microbiome-testing-–-medcity-news

    Everlywell and Jona partner to expand access to gut microbiome testing – MedCity News

    do-you-want-god-or-just-his-answer?

    Do you want God or just His answer?

    the-best-way-to-exfoliate-for-smooth,-glowing-skin-(without-overdoing-it)

    The Best Way to Exfoliate for Smooth, Glowing Skin (Without Overdoing it)

    how-to-keep-your-home-comfortable-and-pest-free-all-year-round-|-live-better

    How To Keep Your Home Comfortable And Pest-Free All Year Round | Live Better

    5-powerful-ways-god-heals-you-after-a-job-loss

    5 Powerful Ways God Heals You After a Job Loss

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • News
    • All
    • Business
    • Science

    Russian tanker approaches Cuba, Trump de facto softens blockade rhetoric

    trump-reverses-cuba-oil-blockade,-says-he-has-‘no-problem’-with-russian-tanker-delivering-fuel

    Trump reverses Cuba oil blockade, says he has ‘no problem’ with Russian tanker delivering fuel

    trump-says-his-‘preference’-would-be-to-‘take-oil-from-iran’

    Trump says his ‘preference’ would be to ‘take oil from Iran’

    fuel-tax-halved,-free-public-transport-offered-as-war-drives-up-prices-in-australia

    Fuel tax halved, free public transport offered as war drives up prices in Australia

    netanyahu-says-latin-patriarch-will-have-full-access-to-jerusalem-holy-site

    Netanyahu says Latin Patriarch will have full access to Jerusalem holy site

    Thieves steal paintings by Renoir, Cézanne and Matisse in three-minute Italian heist

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Business
  • Politics
  • World
  • Review

    Best Gaming Cryptos and Metaverse for 2022

    Apple’s Mac Pro desktop with M2 Ultra chipset is discontinued almost three years after launch

    Top 5 blockchains for 2022: Ethereum, Avalanche, Polygon, more

    Best DeFi cryptos for 2022: Aave, Balancer, PancakeSwap, more

    Best ways to exchange cryptocurrencies for 2022: Bitcoin, Dash, Litecoin, etc.

    Apple reportedly opens Siri to Gemini, Claude and other third-party AI assistants with iOS 27

No Result
View All Result
Vidianews
No Result
View All Result
Home Tech

Major compromise of telnyx PyPI library could put millions of users at risk

Ivan Mehta by Ivan Mehta
March 30, 2026
in Tech
0
major-compromise-of-telnyx-pypi-library-could-put-millions-of-users-at-risk

Major compromise of telnyx PyPI library could put millions of users at risk

0
SHARES
0
VIEWS
Share on FacebookShare on Twitter
World Password Day 2025
(Image credit: Shutterstock)

  • JFrog reports that Telnyx PyPI package was poisoned with malware by TeamPCP
  • Malicious update delivered hidden .wav payload that deployed information theft and persistence mechanisms
  • Users are advised to downgrade, block C2 communication, rotate credentials, and check for persistence.

Telnyx, a popular PyPI package offering real-time communication features, was recently poisoned and used to deliver malware to its users, experts have warned.

A report from security researchers JFrog, along with other independent security experts, shows how, as a cloud platform that allows developers to add real-time communications capabilities to applications, such as voice and messaging, Telnyx provides APIs and tools to create solutions such as calling systems and SMS-based services.

It has already been downloaded millions of times and, according to JFrog, it has had over 670,000 downloads this month, acting as an alternative to Twilio, sometimes chosen due to its asynchronous httpx support and its cost effectiveness in high concurrency environments.

Article continues below

Two poisonous versions

However, telnyx was recently updated, with two new versions on PyPI: 4.87.1 and 4.87.2. Those who upgraded their packages then received a normal audio (.wav) file from the Internet, which the script extracted and decoded.

The malicious code hidden there is used to establish persistence on the target device and deploy second-stage malware that acts as an information stealer, harvesting device data such as login credentials and system information.

The attack was carried out by a hacker collective calling itself TeamPCP. This group recently made headlines when they managed to compromise another major Python package called LiteLLM.

Now, researchers have observed nearly identical code in telnyx, saying they don’t yet know how the maintainer’s PyPI account was compromised.

Sign up for the TechRadar Pro newsletter to get all the top news, opinions, features and tips your business needs to succeed!

In any case, the .wav payload is now offline and the URL hosting it is offline. Those who installed the poisoned versions should upgrade to the clean version, block all communications with the C2 address, then revoke and alternate all credentials. Next, they should seek additional persistence, to ensure that the trade-off has been fully resolved.

Protect WordPress sites

Person editing a WordPress site

WordPress is a major website building platform (Image credit: Pixabay)

As a platform, WordPress is generally considered secure and without known major vulnerabilities. However, it leverages a large repository of user-created third-party themes and plugins, divided into free and premium categories. These are usually accompanied by a dedicated maintenance and development team and, as such, are regularly updated and hardened against attacks.

Free versions, on the other hand, are often created by enthusiasts, small teams, and independent developers. Many of them are abandoned, unmaintained or poorly managed, although they are popular among users. As such, they create a huge security risk on one side and attack opportunities on the other.

Typically, security researchers advise WordPress users to keep their platform, themes, and plugins up to date at all times. Additionally, they suggest users to only keep installed themes and plugins that they actively use and make sure to override all default security and privacy settings.

Via BeepComputer


Best Antivirus Software

Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds. Make sure to click the Follow button!

And of course you can too follow TechRadar on TikTok for news, reviews, unboxings in video form and receive regular updates from us on WhatsApp Also.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). During his career, which spans more than a decade, he has written for numerous media outlets, including Al Jazeera Balkans. He has also hosted several modules on content writing for Represent Communications.

Related
Ivan Mehta

Ivan Mehta

Stay Connected

  • 99 Subscribers
  • Trending
  • Comments
  • Latest
european-markets-in-mixed-territory-after-a-positive-start

European markets in mixed territory after a positive start

January 26, 2026
nascar-driver-denny-hamlin-breaks-silence-after-father-dies-in-house-fire

NASCAR driver Denny Hamlin breaks silence after father dies in house fire

December 31, 2025
tcl-lost-a-lawsuit-claiming-its-qled-tvs-are-not

TCL lost a lawsuit claiming its QLED TVs are not

March 13, 2026
fivio-foreign-checks-himself-into-a-$10,000-rehab-center-to-get-his-mind-straight

Fivio Foreign checks himself into a $10,000 rehab center to get his mind straight

December 31, 2025
hansmaker-presents-the-d1-ultra:-a-dual-laser-engraver-designed-for-each-material-–-techenger

Hansmaker presents the D1 Ultra: a dual laser engraver designed for each material – Techenger

0
nascar-driver-denny-hamlin-breaks-silence-after-father-dies-in-house-fire

NASCAR driver Denny Hamlin breaks silence after father dies in house fire

0
fivio-foreign-checks-himself-into-a-$10,000-rehab-center-to-get-his-mind-straight

Fivio Foreign checks himself into a $10,000 rehab center to get his mind straight

0
david-beckham-leaves-brooklyn-for-his-2025-instagram-tribute-amid-family-feud

David Beckham leaves Brooklyn for his 2025 Instagram tribute amid family feud

0
a-new-covid-variant-is-spreading-in-the-united-states.-how-worried-should-you-be?

A new COVID variant is spreading in the United States. How worried should you be?

March 30, 2026
these-snakes-steal-poison-from-their-prey-–-here

These snakes steal poison from their prey – here

March 30, 2026
treasury-yields-fall-as-traders-reduce-bets-on-fed-rate-cuts

Treasury yields fall as traders reduce bets on Fed rate cuts

March 30, 2026

Department of Labor Proposed 401(k) Alternative Asset Rule

March 30, 2026

Recent News

a-new-covid-variant-is-spreading-in-the-united-states.-how-worried-should-you-be?

A new COVID variant is spreading in the United States. How worried should you be?

March 30, 2026
these-snakes-steal-poison-from-their-prey-–-here

These snakes steal poison from their prey – here

March 30, 2026
treasury-yields-fall-as-traders-reduce-bets-on-fed-rate-cuts

Treasury yields fall as traders reduce bets on Fed rate cuts

March 30, 2026

Department of Labor Proposed 401(k) Alternative Asset Rule

March 30, 2026
Vidianews

Trusted news coverage delivering accurate reporting, breaking headlines, and insightful analysis on global events, business, politics, and tech.

Follow Us

Browse by Category

  • Business
  • Entertainment
  • Faith
  • Gadget
  • Gaming
  • General
  • Health
  • Lifestyle
  • Movie
  • News
  • Politics
  • Review
  • Science
  • Sports
  • Startup
  • Tech
  • Travel
  • World

Recent News

a-new-covid-variant-is-spreading-in-the-united-states.-how-worried-should-you-be?

A new COVID variant is spreading in the United States. How worried should you be?

March 30, 2026
these-snakes-steal-poison-from-their-prey-–-here

These snakes steal poison from their prey – here

March 30, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© © Copyrights 2026 Vidianews. All Rights Reserved. Designed by Vidianews

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result

© © Copyrights 2026 Vidianews. All Rights Reserved. Designed by Vidianews

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
Go to mobile version