The break here is not just malicious code in public registries. TeamPCP is abusing the trust markers developers rely on — a verified VS Code publisher badge and an official Microsoft-published PyPI SDK — so the normal rule of “install from the vendor” no longer holds as a safety signal.
The campaign now spans Visual Studio Marketplace, PyPI, and npm at the same time. A malicious Nx Console extension with the nrwl.angular-console verified-publisher badge was tied to GitHub-internal repo theft, durabletask on PyPI was trojanized in versions 1.4.1 through 1.4.3, and 639 malicious versions were pushed across 323 @antv npm packages, including high-traffic libraries like echarts-for-react and size-sensor.
That pattern points to publisher-account or CI compromise, not isolated bad uploads. The risk persists after the poisoned version is removed, because the trust source itself may already be burned.