Open Internet by MindsNet
Malicious Package Compromise in Python Ecosystem
The telnyx PyPI package was compromised with malicious code in versions 4.87.1 and 4.87.2, which executes on import and pulls a payload from a WAV file. This incident highlights a security vulnerability in the Python package ecosystem, potentially affecting projects that used these versions. The payload's delivery method, reconstructing from audio frame data, makes detection difficult.
Computing & Technology, Computer Science, Programming Languages