Trusted Package Channels Became the Attack Vector

The break here is not just malicious code in public registries. TeamPCP is abusing the trust markers developers rely on — a verified VS Code publisher badge and an official Microsoft-published PyPI SDK — so the normal rule of “install from the vendor” no longer holds as a safety signal. The campaign now spans Visual Studio Marketplace, PyPI, and npm at the same time. A malicious Nx Console extension with the nrwl.angular-console verified-publisher badge was tied to GitHub-internal repo theft, durabletask on PyPI was trojanized in versions 1.4.1 through 1.4.3, and 639 malicious versions were pushed across 323 @antv npm packages, including high-traffic libraries like echarts-for-react and size-sensor. That pattern points to publisher-account or CI compromise, not isolated bad uploads. The risk persists after the poisoned version is removed, because the trust source itself may already be burned.

Part of the PlainSec briefing for 2026-06-08

Sources