MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Telnyx Python SDK supply-chain compromise publishes malicious PyPI releases

On 27 March 2026, unauthorized Telnyx Python SDK versions 4.87.1 and 4.87.2 were published to PyPI containing malicious credential-stealing code. The packages were available through Telnyx's trusted SDK distribution channel from 03:51 UTC until quarantine at 10:13 UTC, exposing developers, CI/CD pipelines and downstream dependencies that installed an unpinned version during that window. Telnyx stated that its platform, APIs, voice, messaging and production infrastructure were not compromised; the material TRACE impact is the corruption of a legitimate software distribution channel.

69

Estimated severity

69 / 100

94

Source reliability

94 / 100

Approximate Date

27/03/2026

Targeted Company

TELNYX

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

No other affected countries reported

Target country

United States

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT ServicesTelecommunications

Affected departments

Information TechnologyEngineering & Maintenance

Attack Profile

Attack types

Software supply chain compromiseMalware

Attributed threat actors

TEAMPCP

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.