Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Latest PyPi Compromise

t.m-kosche.com

TLP:CLEAR
Active

Domain

Description

A supply chain attack targeting the Microsoft DurableTask Python client compromised versions 1.4.1, 1.4.2, and 1.4.3 on PyPi. The threat actor gained access through a compromised GitHub account previously linked to attacks, using stolen credentials to dump GitHub secrets containing PyPi tokens. The evolved payload targets Linux systems, stealing credentials from AWS, Azure, GCP, Kubernetes, Vault, and password managers like Bitwarden and 1Password. It propagates via AWS SSM and Kubernetes lateral movement, limited to 5 targets per infected host. The payload scrapes shell history, bruteforces password managers, and establishes persistence through infection markers. Compromised packages were quarantined following analysis.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Latest PyPi Compromise
Pattern Type
STIX
Confidence
75%
Valid From
May 21, 2026 03:05
Total Sightings
0
Added
May 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of t.m-kosche.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.