VDB

GCVE-110-OSM-2026-1072

GCVE-110-OSM-2026-1072
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published March 27, 2026
Legitimate Telnyx Python SDK compromised on PyPI via stolen CI/CD credentials as part of the TeamPCP campaign. Malicious versions 4.87.1 and 4.87.2 inject code at import-time in telnyx/_client.py (line 459) that downloads WAV files containing steganographically embedded payloads. Windows variant drops XOR-obfuscated executable as msbuild.exe in startup folder; Linux/macOS variant decodes a Python credential collector from WAV frame data and exfiltrates data as tpcp.tar.gz encrypted with AES-256-CBC and RSA-4096 key wrapping. === PAYLOAD 1: Import-time Injection === Malicious payload found in: telnyx/_client.py (line 459) Behavior: Base64-encoded second-stage Python script injected at import time === PAYLOAD 2: Windows Variant === C2: 83.142.209.203:8080 Downloads: hangup.wav (XOR-obfuscated executable, first 8 bytes as key) Drops: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\msbuild.exe Persistence: 12-hour re-drop cooldown via msbuild.exe.lock file === PAYLOAD 3: Linux/macOS Variant === C2: 83.142.209.203:8080 Downloads: ringtone.wav (base64-encoded Python collector in WAV frame data) Exfiltration: tpcp.tar.gz with AES-256-CBC encryption, RSA-4096 wrapped session key === FILE HASHES (SHA256) === telnyx 4.87.1 wheel: 7321caa303fe96ded0492c747d2f353c4f7d17185656fe292ab0a59e2bd0b8d9 telnyx 4.87.2 wheel: cd08115806662469bbedec4b03f8427b97c8a4b3bc1442dc18b72b4e19395fe3

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowntelnyx* (affected)

References

vendor

Browse GCVE Records

74,237 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›