1.1M Downloads: Major PyPI Package Hacked to Distribute Infostealer

Date:

Malicious Python Package Compromises Developer Data

In a recent cybersecurity incident, a malicious version of the popular Python package, elementary-data, was uploaded to the Python Package Index (PyPI), targeting sensitive developer information and cryptocurrency wallets. The malicious release, version 0.23.3, was able to infiltrate the community due to a flaw in the development workflow, allowing the attacker to execute harmful code.

The attack affected data and analytics engineers using the elementary-data package, which garners over 1.1 million downloads monthly. Users who installed the malicious package may have had their SSH keys, cloud credentials, and cryptocurrency wallet files exposed.

To protect against this threat, users are advised to rotate all secrets and revert their systems to a safe state if they downloaded the compromised version.

Risk Level: High
This incident highlights the ongoing vulnerabilities in open-source ecosystems, emphasizing the need for vigilant security practices.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...