← Back to Feed

TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM

March 30, 2026 · Trend Micro · Severity: MEDIUM

Moving beyond their LiteLLM campaign, TeamPCP weaponizes the Telnyx Python SDK with stealthy WAV‑based payloads to steal credentials across Linux, macOS, and Windows.

Key Takeaways

  • TeamPCP weaponized the Telnyx Python SDK with stealthy WAV-based payloads to steal credentials across Linux, macOS, and Windows.
  • The Telnyx SDK attack marks a shift in TeamPCP's tactics beyond their earlier LiteLLM campaign, expanding credential theft to more platforms.
  • Organizations using Telnyx SDK artifacts should verify package integrity and audit dependencies in build pipelines.
☕ Buy a Coffee