VDB
GCVE-110-OSM-2026-1072
GCVE-110-OSM-2026-1072
Advisory PublishedCVSS 9.6/10
Legitimate Telnyx Python SDK compromised on PyPI via stolen CI/CD credentials as part of the TeamPCP campaign. Malicious versions 4.87.1 and 4.87.2 inject code at import-time in telnyx/_client.py (line 459) that downloads WAV files containing steganographically embedded payloads. Windows variant drops XOR-obfuscated executable as msbuild.exe in startup folder; Linux/macOS variant decodes a Python credential collector from WAV frame data and exfiltrates data as tpcp.tar.gz encrypted with AES-256-CBC and RSA-4096 key wrapping.
=== PAYLOAD 1: Import-time Injection ===
Malicious payload found in: telnyx/_client.py (line 459)
Behavior: Base64-encoded second-stage Python script injected at import time
=== PAYLOAD 2: Windows Variant ===
C2: 83.142.209.203:8080
Downloads: hangup.wav (XOR-obfuscated executable, first 8 bytes as key)
Drops: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\msbuild.exe
Persistence: 12-hour re-drop cooldown via msbuild.exe.lock file
=== PAYLOAD 3: Linux/macOS Variant ===
C2: 83.142.209.203:8080
Downloads: ringtone.wav (base64-encoded Python collector in WAV frame data)
Exfiltration: tpcp.tar.gz with AES-256-CBC encryption, RSA-4096 wrapped session key
=== FILE HASHES (SHA256) ===
telnyx 4.87.1 wheel: 7321caa303fe96ded0492c747d2f353c4f7d17185656fe292ab0a59e2bd0b8d9
telnyx 4.87.2 wheel: cd08115806662469bbedec4b03f8427b97c8a4b3bc1442dc18b72b4e19395fe3
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | telnyx | * (affected) | — |
Browse GCVE Records
74,237 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.