1.1M Downloads: Major PyPI Package Hacked to Distribute Infostealer

Date:

Malicious Python Package Compromises Developer Data

In a recent cybersecurity incident, a malicious version of the popular Python package, elementary-data, was uploaded to the Python Package Index (PyPI), targeting sensitive developer information and cryptocurrency wallets. The malicious release, version 0.23.3, was able to infiltrate the community due to a flaw in the development workflow, allowing the attacker to execute harmful code.

The attack affected data and analytics engineers using the elementary-data package, which garners over 1.1 million downloads monthly. Users who installed the malicious package may have had their SSH keys, cloud credentials, and cryptocurrency wallet files exposed.

To protect against this threat, users are advised to rotate all secrets and revert their systems to a safe state if they downloaded the compromised version.

Risk Level: High
This incident highlights the ongoing vulnerabilities in open-source ecosystems, emphasizing the need for vigilant security practices.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...