← Elementary Data

2026 Elementary Data - PyPI/GHCR supply-chain compromise via GitHub Actions injection

2026 Unknown records affected Share on X

Data compromised

Developer secrets, cloud access tokens, API keys, and cryptocurrency wallet material on systems that installed the malicious package

Technical writeup

UpGuard reported that Elementary Data disclosed a high-severity supply-chain compromise affecting the elementary-data PyPI package and related GHCR Docker images. Attackers exploited a script-injection vulnerability in the GitHub Actions pipeline, forged a verified release commit, and distributed malicious version 0.23.3. The malicious package activated on installation and targeted developer secrets such as cloud access tokens and cryptocurrency wallets. Versions 0.23.4 and 0.23.2 were described as unaffected.

Root cause

Script-injection vulnerability in GitHub Actions release pipeline enabling malicious PyPI and Docker package release

References