The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised
Blog post from Snyk
A new security compromise has emerged in the Python ecosystem, targeting the "durabletask" package, which is linked to Microsoft's Durable Task Framework. This incident follows a similar pattern to the recent compromise of the guardrails-ai package and is part of a broader campaign known as Shai Hulud. The malicious version of durabletask, which has been removed from the PyPI registry, contains a payload that can steal credentials, propagate to other environments, and destroy data, specifically affecting Linux systems. Despite durabletask's relatively modest download numbers compared to other affected packages, its association with Microsoft raises concerns about potential future attacks on major technology companies' projects. Users are advised to check their dependency trees, scan projects with Snyk, and rotate any compromised credentials, particularly if running the package on Linux.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 1 | 2,324 | 403 | 114 | +18% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.