Observed Signal · Apr 29, 2026 · Supply Chain Attack · Source: DEV Community · Impact: 4/5 · Sentiment: Negative

Malicious elementary-data PyPI Release Steals Credentials

Executive Signal Summary

A malicious version (0.23.3) of the widely used Python package elementary-data was published to PyPI after attackers exploited a GitHub Actions workflow injection. The package contained an elementary.pth startup hook that harvested a broad set of credentials (dbt profiles, cloud provider keys, SSH keys, kube/configs, package manager tokens, cryptocurrency wallets) and exfiltrated them to a command-and-control domain. The compromise was live on PyPI from April 24–25, 2026 and was removed after community reporting; Snyk assigned the issue a Critical severity (CVSS v4.0: 9.3) and published advisory SNYK-PYTHON-ELEMENTARYDATA-16316110. Remediation steps include upgrading to elementary-data>=0.23.4, rotating potentially exposed credentials, removing cached .pth artifacts, pulling clean Docker images, and hardening GitHub Actions (use short-lived OIDC tokens / Trusted Publishers and avoid unquoted context interpolation).

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

High-severity supply-chain compromise of a widely used data engineering package that exposed cloud and CI credentials across Snowflake/BigQuery/Redshift and major cloud providers; requires credential rotation, CI workflow hardening, and has cross-industry impact on data infrastructure.

SIGNAL RADAR

Track LiteLLM Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Malicious package published: elementary-data==0.23.3 (published April 24, 2026 at 22:20 UTC).
  • Severity: Critical (Snyk advisory SNYK-PYTHON-ELEMENTARYDATA-16316110; CVSS v4.0: 9.3).
  • Attack vector: GitHub Actions workflow comment/script injection (attacker used forged commits and the repository's release workflow to publish the malicious release).
  • Payload: a site-packages file elementary.pth that executed at Python startup to harvest credentials (dbt, Snowflake/BigQuery/Redshift, AWS/GCP/Azure keys, SSH keys, Kubernetes tokens, package manager tokens, .env files, crypto wallets) and exfiltrated them to igotnofriendsonlineorirl-imgonnakmslmao.skyhanni.cloud.
  • Remediation: upgrade to elementary-data>=0.23.4 (0.23.4 published April 25, 2026), rotate exposed credentials, remove elementary.pth artifacts, and audit GitHub Actions workflows; compromised Docker image digest sha256:31ecc5939de6d24cf60c50d4ca26cf7a8c322db82a8ce4bd122ebd89cf634255.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Apr 29, 2026
Original Coverage Title: “Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Large Language Models (LLM) & AIMar 27, 2026

LiteLLM PyPI Backdoor Exposes Python LLM Gateway Risk

On March 24, 2026, threat actor group TeamPCP used stolen CI credentials (exfiltrated via a compromised Trivy GitHub Action) to publish two backdoored LiteLLM releases (1.82.7 and 1.82.8) to PyPI. The multi-stage malware harvested SSH keys, cloud (AWS/GCP/Azure) credentials, Kubernetes secrets, cryptocurrency wallets, and installed persistent backdoors; exfiltration used models.litellm.cloud. Version 1.82.8 employed a litellm_init.pth startup hook that ran on interpreter start, widening impact beyond explicit imports. Snyk, Wiz, FutureSearch and LiteLLM published technical analyses and mitigations. The incident highlights systemic Python supply-chain risks for LLM gateways (packages that hold provider API keys) and recommends immediate steps: check versions, scan for malicious .pth files, rotate credentials, pin dependencies and CI actions, and consider compiled or managed gateway alternatives.

Read assessment
Security / LLM Supply ChainMar 25, 2026

Litellm PyPI Supply-Chain Attack Targets LLM API Keys

Two malicious Litellm releases (notably v1.82.8) on PyPI contained a multi-stage backdoor that exfiltrated environment variables, LLM API keys, SSH keys, cloud credentials, Kubernetes configs and crypto wallets before being removed. The compromised package was discovered as a transitive dependency inside Cursor when an MCP plugin pulled it. Security vendors (GitGuardian, Snyk, JFrog, Endor Labs) and high-profile posts amplified the incident. The article argues the root reason the attack succeeded is common patterns in so‑called "vibe‑coded" apps: transitive dependencies, absent security reviews of AI-generated code, and insecurely stored credentials. Large scans (Escape.tech and others) reportedly found thousands of vulnerabilities and hundreds of exposed secrets in vibe-coded projects. The piece lists a five-step rapid audit and promotes VibeCheck (a free scanner) plus a paid Vibe Coding Security Playbook with remediation prompts.

Read assessment
InfrastructureMay 31, 2026

23,000+ Repos Had Secrets Stolen via Compromised GitHub Action

A DevOps/security post documents a major supply-chain compromise of GitHub Actions where a popular action (tj-actions/changed-files) was hijacked in March 2025, exposing AWS keys, GitHub PATs, RSA private keys and npm tokens for over 23,000 teams. The vulnerability was tracked as CVE-2025-30066. The author analyzes this and related incidents (Ultralytics December 2024, Trivy February 2026), identifies recurring root causes (tag-pinned actions, pull_request_target misuse, overly permissive GITHUB_TOKEN scopes) and presents seven practical CI/CD hardening techniques: pin actions to commit SHAs, use OIDC, restrict GITHUB_TOKEN permissions, treat workflow files like production code, use automated workflow scanners (e.g., Zizmor), mirror critical actions/private registries, and enforce branch protection and deployment gates. The piece includes a checklist of quick wins and describes how the author applied these principles while building Nexloy.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.