MEDIUMSupply Chain
Global

The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised

·Source: Snyk

Updated:

Executive Summary

A day after the AntV npm supply chain attack, the same campaign appears to have struck `durabletask`, a Microsoft-associated Python package on PyPI. Snyk has coverage in the vulnerability database and package health pages. Here's what we know.

Analysis

A day after the AntV npm supply chain attack, the same campaign appears to have struck `durabletask`, a Microsoft-associated Python package on PyPI. Snyk has coverage in the vulnerability database and package health pages. Here's what we know.
Source Attribution

Originally published by Snyk on May 19, 2026.

Related Threats