Microsoft DurableTask Python Client Compromised by TeamPCP
ID: 91acaff6-fa22-5d5a-ac81-6c7e16fe7250
STIX ID: report--91acaff6-fa22-5d5a-ac81-6c7e16fe7250
Feed Name: Cyber Press
Researchers attribute a high-impact supply-chain compromise to TeamPCP (Mini Shai-Hulud campaign), where three malicious durabletask Python client releases were uploaded to PyPI on May 19, 2026 by abusing stolen GitHub/GitHub Actions secrets and a PyPI token. The lightweight dropper fetched a zipapp payload that steals cloud and local credentials across AWS, Azure, GCP, Kubernetes, and vaults, propagates laterally via SSM and kubectl, and exfiltrates to C2 domains (check.git-service.com / t.m-kosche.com); the report provides hashes, IoCs, and mitigation steps including credential rotation and blocking C2 endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
