On May 19, 2026, the official Microsoft durabletask Python SDK was compromised on PyPI. Threat actors used hijacked publishing credentials to directly upload malicious versions containing a cloud credential-harvesting payload.
#package-compromise
5 analyses tagged package-compromise, sorted newest first.
- Microsoft DurableTask Python SDK PyPI Hijacking
- Node-IPC Expired Domain & Maintainer Account Hijacking
On May 14, 2026, the highly popular Node.js library node-ipc was compromised in a major supply chain attack. Attackers re-registered the expired email domain of a dormant lead maintainer to reset their npm account password and publish credential-stealing updates.
- intercom-client npm Mini Shai-Hulud Compromise
Intercom says an attacker published `[email protected]` on April 30, 2026 using credentials from a compromised developer account. The package executed a Bun-launched credential stealer during installation and was removed within hours.
- Lightning PyPI Bun-Based Credential Stealer
On April 30, 2026, malicious `lightning` PyPI releases 2.6.2 and 2.6.3 shipped an import-time loader that bootstrapped Bun and executed a large obfuscated JavaScript credential stealer.
- LiteLLM Python SDK PyPI Hijacking & Cascading Trust Failure
On March 24, 2026, the popular LiteLLM Python package was compromised on PyPI. Attackers harvested PyPI publishing secrets from LiteLLM's CI/CD runner via a previously backdoored dependency, uploading malicious versions containing a python startup hook payload.