Microsoft DurableTask Python Client Targeted in TeamPCP Cyberattack
ID: 2ef4d8bf-e958-53b7-b433-f2b935e31b67
STIX ID: report--2ef4d8bf-e958-53b7-b433-f2b935e31b67
Feed Name: GBHackers
Threat Score
**Executive summary:** The TeamPCP campaign trojanized Microsoft DurableTask Python client packages (durabletask versions 1.4.1–1.4.3) on PyPI, delivering a rope.pyz payload that steals AWS/Azure/GCP/Kubernetes/Vault credentials, scrapes local password managers and shell history, and propagates via AWS Systems Manager and Kubernetes; PyPI quarantined the malicious versions and the report provides C2 domains, filesystem artifacts, and recommended detection and remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
