logo

Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts

ID: f5fbacd2-b48f-5c7f-8372-be04bbd81635

STIX ID: report--f5fbacd2-b48f-5c7f-8372-be04bbd81635

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Abinaya

...
...

**Supply-chain compromise of elementary-data (PyPI & GHCR):** A malicious release (elementary-data v0.23.3) and corresponding Docker image were published after attackers injected code into a GitHub Actions workflow via a PR comment, using the workflow token to forge a verified release. The package drops an elementary.pth information-stealer that exfiltrates cloud tokens, SSH/Git keys, Kubernetes/Docker credentials, .env files, and cryptocurrency wallets; the malicious artifacts were removed and a clean v0.23.4 released—affected users must rotate credentials, enable MFA, and pin package versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.