2026 Elementary Data - PyPI/GHCR supply-chain compromise via GitHub Actions injection
Data compromised
Developer secrets, cloud access tokens, API keys, and cryptocurrency wallet material on systems that installed the malicious package
Technical writeup
UpGuard reported that Elementary Data disclosed a high-severity supply-chain compromise affecting the elementary-data PyPI package and related GHCR Docker images. Attackers exploited a script-injection vulnerability in the GitHub Actions pipeline, forged a verified release commit, and distributed malicious version 0.23.3. The malicious package activated on installation and targeted developer secrets such as cloud access tokens and cryptocurrency wallets. Versions 0.23.4 and 0.23.2 were described as unaffected.
Root cause
Script-injection vulnerability in GitHub Actions release pipeline enabling malicious PyPI and Docker package release