Malicious Python package poses new supply chain threat

TL;DR AI
2 min readKey summary
Attackers abused a GitHub Actions flaw in elementary-data to steal secrets and signing keys.
They pushed a malicious 0.23.3 release to PyPI and Docker, putting infected builds in circulation for about 12 hours.
The malware targeted developer and CI/CD environments to steal credentials, making this a high-impact supply chain attack.
Users of version 0.23.3 should remove it, upgrade immediately, and rotate any exposed credentials.



