As cited
Copy frozen at (site build).
threat intel
durabletask: TeamPCP's Latest PyPi Compromise
A malicious version of the durabletask package was discovered on the Python Package Index (PyPI), following tactics consistent with TeamPCP. The compromise targeted developers using this dependency management platform. This represents another instance of supply chain threats through package repository manipulation.
Why it matters: Developers and organizations using durabletask or similar PyPI packages face immediate risk of compromise through dependency installation; practitioners should audit package versions and implement package verification controls.
- Source published
- First seen by Cybersecurity Tracker