Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the durabletask package.
durabletask is an A Durable Task Client SDK for Python
Affected versions of this package are vulnerable to Embedded Malicious Code that conceals a malicious payload. A malicious actor linked to the @antv appears to have compromised the GitHub account associated with the package and dumped repository secrets to extract a PyPI token; This allowed the attacker to publish tampered versions of the Microsoft durabletask package to PyPI.
According to security reports, the payload is designed to establish communications with external C2 servers and steal credentials from AWS, Azure, GCP, Kubernetes, Vault, and the filesystem. It actively attempts to brute-force password managers like Bitwarden and 1Password, scrapes shell history, and acts as a worm to propagate laterally across AWS SSM and Kubernetes. The malware will persist and leave an infection marker on the system by creating a file at ~/.cache/.sys-update-check or ~/.cache/.sys-update-check-k8s if on Linux. If you find any files in these locations, you have been compromised and should no longer trust the system to be safe.
Notes: