PyPI package with 1.1M monthly downloads hacked to push infostealer
ID: 7df4860d-e63c-5c82-ad99-f597d76028ab
STIX ID: report--7df4860d-e63c-5c82-ad99-f597d76028ab
Feed Name: Bleeping Computer
A malicious 0.23.3 release of the popular elementary-data PyPI package was published after an attacker exploited a GitHub Actions script-injection flaw to exfiltrate the workflow GITHUB_TOKEN and trigger the project's release pipeline; the backdoored package and corresponding Docker image contained an elementary.pth loader that steals developer secrets (SSH/git/cloud creds, CI/container secrets, .env files) and crypto wallet files. Users who fetched elementary-data==0.23.3 or images tagged ghcr.io/elementary-data/elementary:0.23.3 and :latest should rotate all secrets and restore environments from known-good points.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
