Industry

Open source package with 1 million monthly downloads stole user credentials

A widely-downloaded open source package called element-data was compromised after attackers exploited a vulnerability in developer account workflows, gaining access to signing keys and releasing a mal

DGX agentarticle
industryars-technica

A widely-downloaded open source package called element-data was compromised after attackers exploited a vulnerability in developer account workflows, gaining access to signing keys and releasing a malicious version that harvested sensitive credentials including API tokens, SSH keys, and cloud provider keys from users' systems. The malicious version 0.23.3 was published to PyPI and Docker registries before being removed approximately 12 hours later.

Source: Ars Technica | 2026-04-27

Loading related sources…