Bleepingcomputer Malicious PyPI Package Compromises Developer Data and Cryptocurrency Wallets
Article Content
- •A malicious version of the elementary-data package was uploaded to PyPI, affecting over 1.1 million users.
- •The attack exploited a GitHub Actions script injection flaw, allowing unauthorized code execution.
- •Users are advised to rotate secrets and restore environments if they downloaded the compromised package.
A malicious version of the popular Python package elementary-data (version 0.23.3) was uploaded to the Python Package Index (PyPI), targeting sensitive developer information and cryptocurrency wallets. The attack exploited a GitHub Actions script injection flaw, allowing the attacker to execute shell code and expose the GITHUB_TOKEN. This enabled the attacker to forge a signed commit and trigger the legitimate release pipeline, which published the compromised package and a malicious Docker image. Users who downloaded the malicious version remain compromised, and a clean version (0.23.4) has since been released. The incident affects the dbt ecosystem, which has over 1.1 million monthly downloads. Affected users are advised to rotate all secrets and restore their environments from a known safe point. The malicious release included a file that executed a secrets stealer at startup. Systems that did not pin package versions automatically pulled the backdoored build. The incident highlights vulnerabilities in package management workflows.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…