Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Trojanized Microsoft SDK: durabletask 1.4.1 through 1.4.3 Deliver Credential-Stealing Malware

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Peyton Kennedy
Word Count
1,932
Company Posts That Month
25
Language
English
Hacker News Points
-
Post removed?
No
Summary

Endor Labs identified a significant security breach involving three compromised versions of the durabletask package, a Python SDK for Microsoft's Azure Durable Functions, which were discovered on May 19, 2026. These versions, numbered 1.4.1, 1.4.2, and 1.4.3, contained malicious code that executed upon import, posing a severe threat as it targeted various cloud service credentials including AWS, Azure, and GCP, among others. Notably, the malware was designed to operate quietly, without generating errors or visible signs, making detection challenging. It was specifically configured to affect Linux systems and included a payload capable of wiping filesystems and facilitating lateral movement to AWS ECS and Kubernetes pods. The attackers employed sophisticated exfiltration methods, using credentials to interact with GitHub's API for data transfer, and the malware's execution path was meticulously crafted to appear as routine network activity. The incident underscores the importance of vigilant monitoring, restricting CI/CD permissions, and employing hash pinning in software development practices to mitigate such threats.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 11 2,152 360 101 +18%
Kubernetes 8 1,965 371 106 -15%
AI Agents 1 4,942 1,264 250 +12%
Serverless 1 1,797 597 92 +165%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.