Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised

Blog post from Snyk

Post Details
Company
Date Published
Author
Liran Tal
Word Count
522
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

A new security compromise has emerged in the Python ecosystem, targeting the "durabletask" package, which is linked to Microsoft's Durable Task Framework. This incident follows a similar pattern to the recent compromise of the guardrails-ai package and is part of a broader campaign known as Shai Hulud. The malicious version of durabletask, which has been removed from the PyPI registry, contains a payload that can steal credentials, propagate to other environments, and destroy data, specifically affecting Linux systems. Despite durabletask's relatively modest download numbers compared to other affected packages, its association with Microsoft raises concerns about potential future attacks on major technology companies' projects. Users are advised to check their dependency trees, scan projects with Snyk, and rotate any compromised credentials, particularly if running the package on Linux.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 2,324 403 114 +18%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.