Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedhigh

durabletask: TeamPCP's Latest PyPi Compromise

Malicious versions of the PyPI package durabletask were published, attributed to the TeamPCP threat actor. The attack matches known TeamPCP tactics used in prior supply chain compromises.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown scope; PyPI package with potential wide reach depending on adoption.
Ecosystems
Attack vectors
Threat actor
Affected entities
  • durabletaskPyPI package compromised with malicious versions

TeamPCP, a known supply chain threat actor, compromised the durabletask package on PyPI by publishing malicious versions. The incident was reported by Wiz and follows established patterns from prior TeamPCP campaigns targeting package repositories.\n\nThe specific malicious versions and payload details are not disclosed in the summary provided. However, the attack matches recognized TeamPCP operational tactics in previous supply chain incidents.\n\nDownstream users who installed the compromised versions of durabletask are at risk. The full scope of impact and specific versions affected require examination of the full Wiz report."

Indicators of compromise

Packages
  • durabletask

Remediation

  • Immediately audit all systems for installation of durabletask and identify affected versions
  • Remove or upgrade durabletask to a known clean version from PyPI
  • Review package dependencies and supply chain for similar compromises
  • Enable package integrity verification and monitor PyPI for malicious uploads
  • Implement runtime detection for indicators of compromise from malicious durabletask execution

Sources

  1. durabletask: TeamPCP's Latest PyPi Compromise · Wiz

Cite this entry

"durabletask: TeamPCP's Latest PyPi Compromise." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed May 19, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/durabletask-teampcp-s-latest-pypi-compromise-84w43k

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in vtranalytic (PyPI)

    The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.

    PyPICompromised packageMalicious maintainer
  2. containedcritical

    Malicious code in govapkg (PyPI)

    govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.

    PyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in dev-helper-bg (PyPI)

    The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.

    2026 07 Make HelperPyPICompromised packageMalicious commit
  4. containedcritical

    Malicious code in karpatkit (PyPI)

    The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.

    PyPICompromised packageMalicious commit