Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers
A Python package on PyPI called elementary-data, with over 1 million downloads per month, has suffered a supply chain security attack sourced through a GitHub Actions attack vector.
TL;DR
AdvisorySNYK-PYTHON-ELEMENTARYDATA-16316110
SeverityC...
snyksec.hashnode.dev10 min read