Skip to content
Telnyx Python SDK: Supply Chain Security Notice

Telnyx Python SDK: Supply Chain Security Notice

News.Ycombinator • March 27, 2026

On March 27, 2026 at 03:51:28 UTC, two unauthorized versions of the Telnyx Python SDK were published to PyPI: versions 4.87.1 and 4.87.2. Both versions contained malicious code. Both were quarantined by 10:13 UTC the same day.

This incident is part of a broader supply chain campaign that has also affected Trivy, Checkmarx, and LiteLLM.

The Telnyx platform, APIs, and infrastructure were not compromised. This incident was limited to the PyPI distribution channel for the Python SDK.

Both versions have been removed from PyPI.

You may be affected if:

Run the following command:

If the version shown is 4.87.1 or 4.87.2, treat the environment as compromised.

Additional IOCs will be published as the investigation confirms them.

The Telnyx platform, voice services, messaging infrastructure, networking, SIP, AI inference, and all production APIs were not affected.

The SDK is a client library that wraps public APIs. It has no privileged access to Telnyx infrastructure. No customer data was accessed through this incident.

This attack is part of a multi-week supply chain campaign:

[email protected] if you have questions this incident or need assistance determining if your environment was affected.

Extracted Entities

Attack Types (1)

Companies (2)

Platforms (1)

Tools (2)