Top open source PyPI package with over 1 million downloads every month hacked to emit malware


  • A widely used PyPI package was recently compromised through a malicious update
  • The attack leveraged a GitHub Actions workflow to push infostealer code into a release
  • Maintainers quickly issued a clean version, rotated credentials and began an external investigation

A popular Python Package Index (PyPI) package has been compromised and used to deliver malware to its users, experts have warned.

A user recently warned the maintainers of the Elementary package that the latest version, 0.23.3, contained “malicious base64 encoded code”. The maintainers responded quickly, confirming the news, releasing a clean update (0.23.4) and notifying other users.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top