logo

Microsoft DurableTask Python Client Compromised by TeamPCP

ID: 91acaff6-fa22-5d5a-ac81-6c7e16fe7250

STIX ID: report--91acaff6-fa22-5d5a-ac81-6c7e16fe7250

Feed Name: Cyber Press

Threat Score
92/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Lucas Martin

...
...

Researchers attribute a high-impact supply-chain compromise to TeamPCP (Mini Shai-Hulud campaign), where three malicious durabletask Python client releases were uploaded to PyPI on May 19, 2026 by abusing stolen GitHub/GitHub Actions secrets and a PyPI token. The lightweight dropper fetched a zipapp payload that steals cloud and local credentials across AWS, Azure, GCP, Kubernetes, and vaults, propagates laterally via SSM and kubectl, and exfiltrates to C2 domains (check.git-service.com / t.m-kosche.com); the report provides hashes, IoCs, and mitigation steps including credential rotation and blocking C2 endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.