people · May 21, 2026
Snyk Tracks Extension of AntV Supply Chain Campaign into Python via durabletask Package
Share the canonical public link.
Snyk catalogued the malicious PyPI package durabletask as SNYK-PYTHON-DURABLETASK-16761538 on or around May 19, 2026. Snyk updated its package health page and released the Active Security Incident Assessment for Antv Supply Chain Compromise – May 2026 Zero Day Report to customers detailing a dropper payload delivering an infostealer targeting cloud credentials, password managers and developer tools along with worm-like behavior and disk wiper on Linux systems. The compromised release has roughly 103,000 weekly downloads according to Snyk. Snyk previously documented the AntV wave that followed the May 11, 2026 TanStack attack involving 84 malicious versions across 42 packages.