Skip to content
Malicious PyPI Package Compromises Developer Data and Cryptocurrency Wallets

Malicious PyPI Package Compromises Developer Data and Cryptocurrency Wallets

First seen 27 Apr 2026, 18:31 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 28, 2026 at 18:04 UTC
  • •A malicious version of the elementary-data package was uploaded to PyPI, affecting over 1.1 million users.
  • •The attack exploited a GitHub Actions script injection flaw, allowing unauthorized code execution.
  • •Users are advised to rotate secrets and restore environments if they downloaded the compromised package.

A malicious version of the popular Python package elementary-data (version 0.23.3) was uploaded to the Python Package Index (PyPI), targeting sensitive developer information and cryptocurrency wallets. The attack exploited a GitHub Actions script injection flaw, allowing the attacker to execute shell code and expose the GITHUB_TOKEN. This enabled the attacker to forge a signed commit and trigger the legitimate release pipeline, which published the compromised package and a malicious Docker image. Users who downloaded the malicious version remain compromised, and a clean version (0.23.4) has since been released. The incident affects the dbt ecosystem, which has over 1.1 million monthly downloads. Affected users are advised to rotate all secrets and restore their environments from a known safe point. The malicious release included a file that executed a secrets stealer at startup. Systems that did not pin package versions automatically pulled the backdoored build. The incident highlights vulnerabilities in package management workflows.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 155d ago How this analysis works

Timeline

2026-04-23
Malicious version 0.23.3 uploaded to PyPI
2026-04-23
Community member crisperik reports the malicious upload
2026-04-27
Clean replacement version 0.23.4 released
2026-04-27
Users advised to rotate secrets and restore environments

More articles in this cluster (3)