# The AntV Supply Chain Campaign Expands: Microsoft's \`durabletask\` PyPI Package Compromised

DevFeed: [The AntV Supply Chain Campaign Expands: Microsoft's \`durabletask\` PyPI Package Compromised](<https://devfeed.tech/articles/the-antv-supply-chain-campaign-expands-microsoft-s-durabletask-pypi-package-compromised-7899.md>)

Original publisher: [Read original article](<https://snyk.io/blog/durabletask-pypi-supply-chain-attack/>)

Author: Liran Tal

Published: 2026-05-19T23:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [python](<https://devfeed.tech/tags/python.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [windows](<https://devfeed.tech/tags/windows.md>)

## AI overview

Snyk reports that a malicious `durabletask` release was published to PyPI as part of an apparent expansion of the AntV supply-chain campaign. The package contained a dropper and malware capabilities including credential theft, propagation, and destructive disk wiping.

## Source excerpt

A day after the AntV npm supply chain attack, the same campaign appears to have struck `durabletask`, a Microsoft-associated Python package on PyPI. Snyk has coverage in the vulnerability database and package health pages. Here's what we know.