Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers
Apr 29 · 10 min read · A Python package on PyPI called elementary-data, with over 1 million downloads per month, has suffered a supply chain security attack sourced through a GitHub Actions attack vector. TL;DR AdvisorySNYK-PYTHON-ELEMENTARYDATA-16316110 SeverityC...
Join discussion


