Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!
ID: 0d53207c-cc15-5d70-b721-61ec030d6a16
STIX ID: report--0d53207c-cc15-5d70-b721-61ec030d6a16
Feed Name: Aikido Security's Blog
**Executive summary:** Malicious versions (1.4.1–1.4.3) of the PyPI package durabletask contained an import-time dropper that downloaded and executed a Python zipapp (rope.pyz) from a C2 domain; the payload selectively runs on Linux, harvests extensive cloud and developer secrets (AWS, Azure, GCP, Docker, Kubernetes, password managers, CI tokens, etc.), exfiltrates encrypted bundles via multiple fallbacks (direct C2, signed GitHub dead-drop, or abusive GitHub repo uploads), propagates through AWS SSM and kubectl to infect other hosts/pods, and can install persistence or execute a destructive wiper when remotely activated. IOCs, hashes, domains, file paths, and mitigation steps (credential rotation, network blocks, artifact checks) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
