Top open source PyPI package with over 1 million downloads every month hacked to deliver malware



  • A widely used PyPI package was recently compromised via a malicious update
  • The attack leveraged a GitHub Actions workflow to include the infostealer’s code in a release.
  • Maintainers quickly issued a clean version, rotated credentials, and began an external investigation.

A popular Python Package Index (PyPI) package has been compromised and used to deliver malware to its users, experts have warned.

A user recently warned the maintainers of the Elementary package that the most recent version, 0.23.3, contained “malicious base64-encoded code.” The maintainers soon responded, confirming the news, releasing a clean update (0.23.4) and notifying other users.

Leave a Comment

Your email address will not be published. Required fields are marked *