[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fN01wOIzz_-nuZC3Da93iV-1J9t2BDfoYMf2XNtoO8Z4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"425e7cd4-7389-4342-a91e-53b5626503f2","backdoored-python-package-delivers-steganographic-malware","c971fad4-1d11-4a49-b785-0b41f16f4283","Backdoored Python Package Delivers Steganographic Malware","TeamPCP hackers compromised the popular Telnyx Python package on PyPI by exploiting stolen publishing credentials to upload malicious versions that hide credential-stealing malware inside WAV audio files using steganography. The attack affected over 740,000 monthly downloads and demonstrates how trusted software repositories can become attack vectors when publisher accounts are compromised. The sophisticated use of steganography to hide malicious payloads in audio files shows how attackers are evolving to evade detection systems. Organizations using compromised packages unknowingly installed malware that steals SSH keys, tokens, and other sensitive credentials, potentially leading to widespread system compromise.","**Immediate actions:**\n- This attack could have been prevented through robust supply chain security practices including multi-factor authentication on all publishing accounts, package signing and verification, automated security scanning of dependencies, and maintaining software bills of materials (SBOMs)\n\n**Long-term improvements:**\n- Organizations should implement dependency pinning, use private package repositories with approved libraries, and establish processes to quickly identify and respond to compromised packages\n\n**Detection measures:**\n- Regular rotation of API keys and publishing credentials, combined with monitoring for unauthorized package updates, would have limited the attack's impact",[12,13,14,15,16,17],"CIS Control 2","CIS Control 16","NIST SP 800-161","NIST SSDF","SLSA Framework","ISO 27001 A.14.2.1","published","2026-03-28T08:52:13.590267+00:00","2026-03-28T08:52:13.499+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fbackdoored-telnyx-pypi-package-pushes-malware-hidden-in-wav-audio\u002F","backdoored-telnyx-pypi-package-pushes-malware-hidden-in-wav-audio","Backdoored Telnyx PyPI package pushes malware hidden in WAV audio",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]