Switch language한국어
Back to the list

Malicious Python package poses new supply chain threat

TL;DR AI

Key summary

2 min read
  1. Attackers abused a GitHub Actions flaw in elementary-data to steal secrets and signing keys.

  2. They pushed a malicious 0.23.3 release to PyPI and Docker, putting infected builds in circulation for about 12 hours.

  3. The malware targeted developer and CI/CD environments to steal credentials, making this a high-impact supply chain attack.

  4. Users of version 0.23.3 should remove it, upgrade immediately, and rotate any exposed credentials.

Read the original