Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts

A major software supply chain attack has compromised the popular Python package elementary-data, exposing thousands of developers to massive credential theft. Threat actors successfully pushed a malicious version, 0.23.3, to the Python Package Index (PyPI) and poisoned the matching Docker images on the GitHub Container Registry (GHCR). With over one million monthly downloads, this widely used dbt […]

The post Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: