Attackers used compromised publishing credentials to push malicious versions 1.4.1, 1.4.2, and 1.4.3 of Microsoft’s official durabletask Python SDK to PyPI, turning a trusted Azure Durable Functions package into a supply-chain malware delivery mechanism. The tampered package inserted a dropper into core files including __init__.py; on Linux systems, importing the library triggered a download-and-execute chain from attacker-controlled infrastructure. Researchers said the last known safe release was 1.4.0, and observed outbound traffic tied to the campaign, including a command-and-control check to check[.]git-service[.]com.
The second-stage payload, identified as rope.pyz, was described as a modular intrusion framework aimed at Linux cloud workloads, Kubernetes clusters, CI/CD runners, and developer environments. Its capabilities included theft of AWS, Azure, GCP, Kubernetes, Vault, GitHub, and password-manager secrets, along with encrypted exfiltration, persistence, lateral movement, and resilient command-and-control using primary domains, GitHub dead drops, and fallback exfiltration through victim GitHub accounts. Analysts also reported multiple evasion features—such as Linux-only execution, Russian locale exclusion, CPU-based sandbox checks, detached subprocess execution, and encrypted communications—and said the malware contained probabilistic destructive logic that could wipe systems when Israeli or Iranian indicators were detected.

Trace attribution and downstream blast radius.
8 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-20, GitHub confirmed a breach involving a poisoned VS Code extension on an employee device and said approximately 3,800 internal repositories were exfiltrated. GitHub stated the incident was limited to internal repositories based on its current assessment and that critical secrets had been rotated, while reporting linked the intrusion to the same infrastructure used in the durabletask supply-chain attack.
After the compromise was identified, PyPI quarantined durabletask versions 1.4.1 through 1.4.3 to limit further installation of the trojanized package. The affected releases had been uploaded using a stolen publishing token tied to the official project.
A May 19, 2026 analysis of WindowsTelemetry.zip and WindowsTelemetry.rar documented a PoisonX infection chain using DLL sideloading, persistence, a vulnerable driver for BYOVD, and a RAT communicating over raw TCP to 101.32.190[.]202:8080. The researchers also published public detection content, including a YARA cluster rule for multiple components.
During investigation of the durabletask incident, StepSecurity reported a monitored GitHub Actions workflow making a network call to check[.]git-service[.]com, consistent with the package's command-and-control behavior. This provided an observed indicator tied to the malicious package activity.
On May 19, 2026, StepSecurity and Upwind publicly reported that Microsoft's durabletask PyPI package had been compromised in a supply-chain attack. Their disclosures described credential theft targeting cloud, Kubernetes, CI/CD, and developer environments, along with evasion and persistence features.
On May 19, 2026, attackers used compromised publishing credentials to upload malicious durabletask versions 1.4.1, 1.4.2, and 1.4.3 to PyPI. The trojanized official package added a Linux-focused dropper that fetched and executed a remote payload when imported.
Before the malicious PyPI release, attackers finalized the remote payload later identified as rope.pyz and prepared supporting infrastructure, including command-and-control and delivery mechanisms. Reporting indicates this setup was in place in advance of the package upload.
The last known safe release of Microsoft's durabletask Python SDK, version 1.4.0, was published to PyPI before the compromise. Later reporting identified this version as the baseline users should pin to or earlier.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
22 references tracked. Mallory keeps watching after this page renders.
safedep.io
Open sourceitnews.com.au
Open sourcesafedep.io
Open sourcesafedep.io
Open sourceapp.stepsecurity.io
Open sourceendorlabs.com
Open sourcegithub.com
Open sourcestepsecurity.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.