Malicious PyPI Package Targets Developers with Stealer Malware
TeamPCP has compromised the Telnyx package on the Python Package Index (PyPI), embedding malware within WAV audio files. This supply chain attack aims to steal sensitive data from developers who download the affected package. The malware operates by exploiting a hidden stealer, posing a significant risk to software development environments and underlining the importance of verifying package integrity before installation.