Trojanized Microsoft SDK: durabletask 1.4.1 through 1.4.3 Deliver Credential-Stealing Malware
Blog post from Endor Labs
Endor Labs identified a significant security breach involving three compromised versions of the durabletask package, a Python SDK for Microsoft's Azure Durable Functions, which were discovered on May 19, 2026. These versions, numbered 1.4.1, 1.4.2, and 1.4.3, contained malicious code that executed upon import, posing a severe threat as it targeted various cloud service credentials including AWS, Azure, and GCP, among others. Notably, the malware was designed to operate quietly, without generating errors or visible signs, making detection challenging. It was specifically configured to affect Linux systems and included a payload capable of wiping filesystems and facilitating lateral movement to AWS ECS and Kubernetes pods. The attackers employed sophisticated exfiltration methods, using credentials to interact with GitHub's API for data transfer, and the malware's execution path was meticulously crafted to appear as routine network activity. The incident underscores the importance of vigilant monitoring, restricting CI/CD permissions, and employing hash pinning in software development practices to mitigate such threats.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 11 | 2,152 | 360 | 101 | +18% |
| Kubernetes | 8 | 1,965 | 371 | 106 | -15% |
| AI Agents | 1 | 4,942 | 1,264 | 250 | +12% |
| Serverless | 1 | 1,797 | 597 | 92 | +165% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.