Endorlabs
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This follows a prior attack on Aqua Security's Trivy vulnerability scanner, where malicious payloads were injected into CI/CD pipelines. The same credential-stealing method was observed in Checkmarx's GitHub Action shortly after the Trivy incident. The attacks involved the use of typosquatting techniques to redirect exfiltrated data to deceptive domains. Security researchers from Wiz confirmed the malicious nature of the DurableTask packages, leading to their quarantine on PyPI. Organizations using these tools are advised to rotate credentials and audit their CI/CD environments for potential exposure. The ongoing nature of these attacks highlights the vulnerabilities in software supply chains and the need for heightened security measures.
Key Points: • TeamPCP compromised Microsoft DurableTask versions 1.4.1 to 1.4.3, injecting malicious code. • The attack pattern was similar to a prior compromise of Aqua Security's Trivy vulnerability scanner. • Organizations are urged to rotate credentials and audit CI/CD environments for exposure.