Developers of the VoIP platform Telnyx have warned users about the compromise of the popular (756,000 downloads per month) telnyx package in the PyPI repository, which implements an SDK for accessing the Telnyx API.
In Linux, the malicious software activated upon importing the module and searched for and sent SSH keys, credentials, environment variable contents, API access tokens, connections to cloud services like AWS, GCP, Azure, and K8s, cryptocurrency wallet keys, database passwords, etc. The data discovered was encrypted using AES-256-CBC + RSA-4096 algorithms and sent via an HTTP POST request to an external host.
Source: linux.org.ru
