Observed Signal · Apr 29, 2026 · Supply Chain Attack · Source: DEV Community · Impact: 4/5 · Sentiment: Negative
Malicious elementary-data PyPI Release Steals Credentials
A malicious version (0.23.3) of the widely used Python package elementary-data was published to PyPI after attackers exploited a GitHub Actions workflow injection. The package contained an elementary.pth startup hook that harvested a broad set of credentials (dbt profiles, cloud provider keys, SSH keys, kube/configs, package manager tokens, cryptocurrency wallets) and exfiltrated them to a command-and-control domain. The compromise was live on PyPI from April 24–25, 2026 and was removed after community reporting; Snyk assigned the issue a Critical severity (CVSS v4.0: 9.3) and published advisory SNYK-PYTHON-ELEMENTARYDATA-16316110. Remediation steps include upgrading to elementary-data>=0.23.4, rotating potentially exposed credentials, removing cached .pth artifacts, pulling clean Docker images, and hardening GitHub Actions (use short-lived OIDC tokens / Trusted Publishers and avoid unquoted context interpolation).
High-severity supply-chain compromise of a widely used data engineering package that exposed cloud and CI credentials across Snowflake/BigQuery/Redshift and major cloud providers; requires credential rotation, CI workflow hardening, and has cross-industry impact on data infrastructure.
Track LiteLLM Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Malicious package published: elementary-data==0.23.3 (published April 24, 2026 at 22:20 UTC).
- Severity: Critical (Snyk advisory SNYK-PYTHON-ELEMENTARYDATA-16316110; CVSS v4.0: 9.3).
- Attack vector: GitHub Actions workflow comment/script injection (attacker used forged commits and the repository's release workflow to publish the malicious release).
- Payload: a site-packages file elementary.pth that executed at Python startup to harvest credentials (dbt, Snowflake/BigQuery/Redshift, AWS/GCP/Azure keys, SSH keys, Kubernetes tokens, package manager tokens, .env files, crypto wallets) and exfiltrated them to igotnofriendsonlineorirl-imgonnakmslmao.skyhanni.cloud.
- Remediation: upgrade to elementary-data>=0.23.4 (0.23.4 published April 25, 2026), rotate exposed credentials, remove elementary.pth artifacts, and audit GitHub Actions workflows; compromised Docker image digest sha256:31ecc5939de6d24cf60c50d4ca26cf7a8c322db82a8ce4bd122ebd89cf634255.
Connected Companies & Entities
3 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
LiteLLM PyPI Backdoor Exposes Python LLM Gateway Risk
On March 24, 2026, threat actor group TeamPCP used stolen CI credentials (exfiltrated via a compromised Trivy GitHub Action) to publish two backdoored LiteLLM releases (1.82.7 and 1.82.8) to PyPI. The multi-stage malware harvested SSH keys, cloud (AWS/GCP/Azure) credentials, Kubernetes secrets, cryptocurrency wallets, and installed persistent backdoors; exfiltration used models.litellm.cloud. Version 1.82.8 employed a litellm_init.pth startup hook that ran on interpreter start, widening impact beyond explicit imports. Snyk, Wiz, FutureSearch and LiteLLM published technical analyses and mitigations. The incident highlights systemic Python supply-chain risks for LLM gateways (packages that hold provider API keys) and recommends immediate steps: check versions, scan for malicious .pth files, rotate credentials, pin dependencies and CI actions, and consider compiled or managed gateway alternatives.
Litellm PyPI Supply-Chain Attack Targets LLM API Keys
Two malicious Litellm releases (notably v1.82.8) on PyPI contained a multi-stage backdoor that exfiltrated environment variables, LLM API keys, SSH keys, cloud credentials, Kubernetes configs and crypto wallets before being removed. The compromised package was discovered as a transitive dependency inside Cursor when an MCP plugin pulled it. Security vendors (GitGuardian, Snyk, JFrog, Endor Labs) and high-profile posts amplified the incident. The article argues the root reason the attack succeeded is common patterns in so‑called "vibe‑coded" apps: transitive dependencies, absent security reviews of AI-generated code, and insecurely stored credentials. Large scans (Escape.tech and others) reportedly found thousands of vulnerabilities and hundreds of exposed secrets in vibe-coded projects. The piece lists a five-step rapid audit and promotes VibeCheck (a free scanner) plus a paid Vibe Coding Security Playbook with remediation prompts.
23,000+ Repos Had Secrets Stolen via Compromised GitHub Action
A DevOps/security post documents a major supply-chain compromise of GitHub Actions where a popular action (tj-actions/changed-files) was hijacked in March 2025, exposing AWS keys, GitHub PATs, RSA private keys and npm tokens for over 23,000 teams. The vulnerability was tracked as CVE-2025-30066. The author analyzes this and related incidents (Ultralytics December 2024, Trivy February 2026), identifies recurring root causes (tag-pinned actions, pull_request_target misuse, overly permissive GITHUB_TOKEN scopes) and presents seven practical CI/CD hardening techniques: pin actions to commit SHAs, use OIDC, restrict GITHUB_TOKEN permissions, treat workflow files like production code, use automated workflow scanners (e.g., Zizmor), mirror critical actions/private registries, and enforce branch protection and deployment gates. The piece includes a checklist of quick wins and describes how the author applied these principles while building Nexloy.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
