• 5 min read
• API Stronghold Team
Your .env File Is the Attack Surface. The Telnyx Backdoor Proves It.
TeamPCP backdoored telnyx 4.87.1 and LiteLLM using the same RSA key infrastructure, targeting environment variables both times. Until you stop storing live credentials in .env, rotation is just cleanup.
supply chain PyPI API keys secrets management AI agents