Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
PyPI Package Compromised by Malicious Scripts

PyPI Package Compromised by Malicious Scripts

Posted on April 28, 2026 By CWS

A significant security breach has targeted the widely-used Python package, elementary-data, potentially compromising the credentials of numerous developers. This incident highlights the vulnerability of software supply chains to cyber threats.

Infiltration of PyPI and GitHub

Cybercriminals managed to introduce a harmful version, 0.23.3, of the popular package onto the Python Package Index (PyPI). Simultaneously, they infiltrated the associated Docker images on the GitHub Container Registry (GHCR), further extending the reach of the attack. Given its over one million monthly downloads, the elementary-data tool became an attractive target for hackers.

Unlike other attacks, this breach did not involve stolen developer passwords. According to researchers from StepSecurity, the vulnerability was exploited via a script-injection flaw in the GitHub Actions pipeline associated with the project.

Mechanism of the Attack

The attackers used a newly-created GitHub account to leave a malicious script in an open pull request comment. Due to inadequate handling by the automated workflow, the system executed the script, allowing the attackers to create a verified release commit using an access token provided by the workflow itself. This allowed them to trigger the official release process without altering the main codebase.

Upon installation, the compromised package introduced a file named elementary.pth into the environment. This file, automatically executed whenever Python starts, deployed a three-stage information-stealing payload targeting sensitive data such as cloud access tokens, SSH keys, and cryptocurrency wallets.

Response and Mitigation

StepSecurity advises checking installed versions to determine if systems are affected. The compromised version is 0.23.3, while versions 0.23.4 and 0.23.2 remain secure. Similarly, users of the Docker image ghcr.io/elementary-data/elementary:0.23.3 should upgrade to a secure version.

Thanks to the swift actions of community members, the malicious version was promptly removed, and a clean update was provided. Developers are urged to rotate all credentials and enable two-factor authentication to safeguard their systems.

For ongoing cybersecurity insights, follow us on Google News, LinkedIn, and X. If you have stories to share, contact us to feature them.

Cyber Security News Tags:cloud security, credential theft, Cybersecurity, developer security, docker images, elementary-data, GitHub actions, information stealer, Malware, PyPI, Python package, software supply chain, StepSecurity, version 0.23.3, version 0.23.4

Post navigation

Previous Post: Spectrum Security Secures $19 Million in Funding
Next Post: Chinese Hacker Extradited to U.S. for COVID Cyberattacks

Related Posts

Hackers Weaponizing Free Trials of EDR to Disable Existing EDR Protections Hackers Weaponizing Free Trials of EDR to Disable Existing EDR Protections Cyber Security News
Critical ProFTPD Vulnerability Allows Remote Code Execution Critical ProFTPD Vulnerability Allows Remote Code Execution Cyber Security News
CISA Warns of Iranian Cyber Actors May Attack U.S. Critical Infrastructure CISA Warns of Iranian Cyber Actors May Attack U.S. Critical Infrastructure Cyber Security News
Microsoft Fixes Vulnerability in Entra Agent ID Administration Microsoft Fixes Vulnerability in Entra Agent ID Administration Cyber Security News
Hackers Exploit Logitech Installer for Banking Trojan Hackers Exploit Logitech Installer for Banking Trojan Cyber Security News
NVIDIA Unveils Open Secure AI Alliance for AI Defense NVIDIA Unveils Open Secure AI Alliance for AI Defense Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts
  • Claude AI Unveils Breakthrough in Cryptanalysis
  • Google Ads Misused to Spread MacSync Infostealer via Fake Claude Guide
  • Apple’s iOS 26.6 Patch Secures Against Critical Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts
  • Claude AI Unveils Breakthrough in Cryptanalysis
  • Google Ads Misused to Spread MacSync Infostealer via Fake Claude Guide
  • Apple’s iOS 26.6 Patch Secures Against Critical Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark