Open source package with 1 million monthly downloads stole user credentials

Open source package with 1 million monthly downloads stole user credentials

A widely-used open-source software package, boasting over one million monthly downloads, has fallen victim to a security breach. A threat actor successfully exploited a vulnerability in the developers' account workflow, gaining access to crucial signing keys and other sensitive information. On a recent Friday, attackers took advantage of this security gap to release a compromised version of element-data, a command-line interface designed to help users monitor performance and detect anomalies in machine-learning systems. Once executed, the malicious package searched for sensitive information, including user profiles, warehouse credentials, cloud provider keys, API tokens, and SSH keys, according to the developers. This harmful version, labeled as 0.23.3, was uploaded to both the developers' Python Package Index and Docker image accounts, only to be removed about 12 hours later, on Saturday. Fortunately, Elementary Cloud, the Elementary dbt package, and other CLI versions remained unaffected. The developers urged anyone who installed version 0.23.3 or ran the compromised Docker image to consider their credentials potentially exposed. The breach occurred when the attackers exploited a flaw in a GitHub action created by the developers. By inserting malicious code into a pull request, they managed to execute a bash script within the developers' account, which then extracted sensitive data. Using the acquired account tokens and signing keys, the attackers published the malicious element-data package, making it nearly indistinguishable from the legitimate version. The developers were alerted to the compromise through a third-party issue report and acted swiftly, removing the package within three hours. To mitigate any further risks, the Element team rotated all credentials that the malicious code could access, addressed the vulnerability, and conducted a thorough audit of their other GitHub actions to ensure no similar flaws exist.

Sources : Ars Technica

Published On : Apr 27, 2026, 21:10

Startups
The Future of Work: Executives Weigh In on AI's Impact on Gen Z Careers

As generative artificial intelligence continues to rise, uncertainty looms for the incoming Gen Z workforce. Leaders fro...

Business Insider | Jul 26, 2026, 10:15
The Future of Work: Executives Weigh In on AI's Impact on Gen Z Careers
AI
Shifting Focus: The Cost-Effectiveness of AI Models Takes Center Stage

In recent years, the AI sector has been intensely focused on identifying the most advanced models. While this pursuit re...

Business Insider | Jul 25, 2026, 13:10
Shifting Focus: The Cost-Effectiveness of AI Models Takes Center Stage
AI
Navigating the AI Landscape: Insights from a Former OpenAI Intern

As the demand for expertise in artificial intelligence surges, many are seeking ways to break into this dynamic field. H...

Business Insider | Jul 26, 2026, 10:10
Navigating the AI Landscape: Insights from a Former OpenAI Intern
Computing
Linux Creator Challenges Developers: Embrace AI or Fork Off!

In a recent discussion surrounding the use of AI in software development, Linus Torvalds, the founder of Linux, voiced h...

Business Insider | Jul 26, 2026, 13:10
Linux Creator Challenges Developers: Embrace AI or Fork Off!
Automotive
Uber's Former CEO Makes Waves with New Ventures Amidst Tesla's Earnings Update

In the ever-evolving landscape of transportation, recent developments have come to the forefront, particularly surroundi...

TechCrunch | Jul 26, 2026, 16:25
Uber's Former CEO Makes Waves with New Ventures Amidst Tesla's Earnings Update
View All News