TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack

TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack

First seen 20 May 2026, 05:52 UTC Aikido.DevEndorlabsWizwww.sysdig.comCybersecuritynews+6 78% similarity 74.0

Article Content

Browse articles
ThreatCluster

The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This follows a prior attack on Aqua Security's Trivy vulnerability scanner, where malicious payloads were injected into CI/CD pipelines. The same credential-stealing method was observed in Checkmarx's GitHub Action shortly after the Trivy incident. The attacks involved the use of typosquatting techniques to redirect exfiltrated data to deceptive domains. Security researchers from Wiz confirmed the malicious nature of the DurableTask packages, leading to their quarantine on PyPI. Organizations using these tools are advised to rotate credentials and audit their CI/CD environments for potential exposure. The ongoing nature of these attacks highlights the vulnerabilities in software supply chains and the need for heightened security measures.

Key Points: • TeamPCP compromised Microsoft DurableTask versions 1.4.1 to 1.4.3, injecting malicious code. • The attack pattern was similar to a prior compromise of Aqua Security's Trivy vulnerability scanner. • Organizations are urged to rotate credentials and audit CI/CD environments for exposure.

ThreatCluster AI

Timeline

2026-03-19
TeamPCP compromises Aqua Security's Trivy
Malicious payloads were injected into CI/CD pipelines affecting thousands of repositories.
Sysdig
2026-05-11
Guardrails-ai package compromised
A similar credential-stealing payload was deployed in the guardrails-ai package, indicating a pattern.
Wiz
2026-05-19
DurableTask package quarantined
Versions v1.4.1, v1.4.2, and v1.4.3 of DurableTask were identified as malicious and quarantined by PyPI.
Wiz
2026-05-20
TeamPCP targets Checkmarx GitHub Action
An identical credential-stealing payload was observed in Checkmarx's GitHub Action shortly after the Trivy attack.
Sysdig
2026-05-20
Cybersecurity news reports on DurableTask compromise
Multiple news outlets reported on the ongoing TeamPCP campaign and its impact on Microsoft’s DurableTask.
Cybersecuritynews

Community

Browse all →