Open source package with 1 million monthly downloads stole user credentials

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

The elementary-data Python CLI package (element-data), with over 1 million monthly downloads, was compromised via a GitHub Actions vulnerability. Attackers exploited a flaw in the developers' CI workflow to gain access to signing keys and account tokens, then published a malicious version (0.23.3) to PyPI and Docker Hub. The malicious package harvested credentials, cloud provider keys, API tokens, and SSH keys from affected systems. The package was live for roughly 12 hours before removal. Users who ran version 0.23.3 or the affected Docker image should assume credential compromise and rotate all secrets.

2m read timeFrom arstechnica.com
Post cover image
Table of contents
Ars VideoHow The Callisto Protocol's Gameplay Was Perfected Months Before Release

Sort: