Microsoft Python Client DurableTask Compromised by TeamPCP Hackers
ID: ee82e315-bf31-5516-9e52-e1537e49b52a
STIX ID: report--ee82e315-bf31-5516-9e52-e1537e49b52a
Feed Name: cybersecurityNews.com
Threat Score
TeamPCP (also tracked as PCPcat/DeadCatx3) compromised Microsoft’s durabletask Python client on PyPI (v1.4.1–1.4.3), inserting a Linux-only worm (rope.pyz) that steals AWS/Azure/GCP/Kubernetes/Vault credentials and brute-forces password managers; the worm propagates via AWS SSM and Kubernetes, uses domain-based C2 (check.git-service.com, t.m-kosche.com), and the report provides IOCs and immediate remedial actions including credential rotation and audit steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
