A day after the AntV npm supply chain attack, the same campaign appears to have struck durabletask, a Microsoft-associated Python package on PyPI. Snyk has coverage in the vulnerability database and package health pages. Here’s what we know.
The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised
calendar_today
May 19, 2026
domain
snyk