Elementary Data Compromised in Supply Chain Attack (Campaign)
ID: 496e9c53-cc8d-5b2d-9c29-39de0d64c38a
STIX ID: report--496e9c53-cc8d-5b2d-9c29-39de0d64c38a
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-04-23
Date Updated: 2026-05-11
Author: [email protected] (Wiz Threat Research)
A malicious supply-chain compromise exploited a GitHub Actions script injection to steal the repository GITHUB_TOKEN, publish a trojanized PyPI package (elementary-data v0.23.3) and a compromised GHCR image. The package included an autostart .pth that executed a three-stage obfuscated credential harvester to collect SSH keys, cloud credentials (AWS/GCP/Azure), Kubernetes secrets, developer tokens, and crypto wallets, then compressed and exfiltrated the data via HTTP POST to a remote C2, impacting consumers of the package and unpinned container images.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
