United States
USA
On 27 March 2026, unauthorized Telnyx Python SDK versions 4.87.1 and 4.87.2 were published to PyPI containing malicious credential-stealing code. The packages were available through Telnyx's trusted SDK distribution channel from 03:51 UTC until quarantine at 10:13 UTC, exposing developers, CI/CD pipelines and downstream dependencies that installed an unpinned version during that window. Telnyx stated that its platform, APIs, voice, messaging and production infrastructure were not compromised; the material TRACE impact is the corruption of a legitimate software distribution channel.
Estimated severity
69 / 100
Source reliability
94 / 100
Approximate Date
27/03/2026
Targeted Company
TELNYX
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
United States
USA
No other affected countries reported
Target country
United States
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Please rotate your phone