Open source package with 1 million monthly downloads stole user credentials

TL;DR AI
2 min readKey summary
The elementary-data 0.23.3 Python package was flagged as malicious and capable of stealing secrets from the runtime environment.
Users were urged to remove version 0.23.3, upgrade to 0.23.4, clear caches, check for a malware marker file, and rotate any exposed credentials.
The compromise matters because the package has about 1 million monthly downloads and could leak developer, cloud, and CI/CD secrets downstream.



