The best open source PyPI package with over 1 million downloads every month, hacked to deliver malware


  • A widely used PyPI package was recently compromised by a malicious update
  • The attack leveraged a GitHub Actions workflow to insert infostealer code into a release.
  • Officials quickly released a clean version, alternated credentials and launched an external investigation.

A popular Python Package Index (PyPI) package has been compromised and used to deliver malware to its users, experts have warned.

A user recently warned the Elementary package maintainers that the latest version, 0.23.3, contained “malicious base64-encoded code.” Officials quickly responded, confirming the news, releasing a clean update (0.23.4), and notifying other users.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top