Vulnerabilities & Exploits · Supply Chain

Trusted Package Channels Became the Attack Vector

The break here is not just malicious code in public registries. TeamPCP is abusing the trust markers developers rely on — a verified VS Code publisher badge and an official Microsoft-published PyPI SDK — so the normal rule of “install from the vendor” no longer holds as a safety signal.

The campaign now spans Visual Studio Marketplace, PyPI, and npm at the same time. A malicious Nx Console extension with the nrwl.angular-console verified-publisher badge was tied to GitHub-internal repo theft, durabletask on PyPI was trojanized in versions 1.4.1 through 1.4.3, and 639 malicious versions were pushed across 323 @antv npm packages, including high-traffic libraries like echarts-for-react and size-sensor.

That pattern points to publisher-account or CI compromise, not isolated bad uploads. The risk persists after the poisoned version is removed, because the trust source itself may already be burned.

1 source · May 25

CVE-2026-45321

NVD KEV

Known exploited · CISA KEV

CVSS 9.6 CRITICAL: on 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. EPSS 2% (81st percentile).

CISA federal remediation date Jun 10

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-05-26

Every edition of this story: Trusted Package Channels Became the Attack Vector

More from today