PyPI supply chain compromise via GitHub Actions → elementary-data backdoored with .pth infostealer (exec on interpreter startup)
A recent supply chain attack targeted the elementary-data Python package on PyPI, where an attacker exploited a GitHub Actions script injection vulnerability to abuse the repository’s GITHUB_TOKEN and push a forged relea
📄
This source provides headlines only. Use the button below to read the complete article on the original site.
📰 Read the original article on r/webdev
Originally published by r/webdev. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.