{"id":14247,"date":"2026-04-28T20:50:52","date_gmt":"2026-04-28T20:50:52","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=14247"},"modified":"2026-04-28T20:50:52","modified_gmt":"2026-04-28T20:50:52","slug":"open-supply-package-deal-with-1-million-month-to-month-downloads-stole-person-credentials","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=14247","title":{"rendered":"Open supply package deal with 1 million month-to-month downloads stole person credentials"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2025\/06\/browser-security-threat-1152x627.jpg\" \/><\/p>\n<p>Open supply software program with greater than 1 million month-to-month downloads was compromised after a risk actor exploited a vulnerability within the builders\u2019 account workflow that gave entry to its signing keys and different delicate data.<\/p>\n<p>On Friday, unknown attackers exploited the vulnerability to push a brand new model of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/elementary-data\/elementary\/pkgs\/container\/elementary\">element-data<\/a>, a command-line interface that helps customers monitor efficiency and anomalies in machine-learning programs. When run, the malicious package deal scoured programs for delicate information, together with person profiles, warehouse credentials, cloud supplier keys, API tokens, and SSH keys, builders <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.elementary-data.com\/post\/security-incident-report-malicious-release-of-elementary-oss-python-cli-v0-23-3\">mentioned<\/a>. The malicious model was tagged as 0.23.3 and was revealed to the builders\u2019 Python Bundle Index and Docker picture accounts. It was eliminated about 12 hours later, on Saturday. Elementary Cloud, the Elementary dbt package deal, and all different CLI variations weren&#8217;t affected.<\/p>\n<h2>Assume compromise<\/h2>\n<p>\u201cCustomers who put in 0.23.3, or who pulled and ran the affected Docker picture, ought to assume that any credentials accessible to the atmosphere the place it ran could have been uncovered,\u201d the builders wrote.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/security\/2026\/04\/open-source-package-with-1-million-monthly-downloads-stole-user-credentials\/\">Learn full article<\/a><\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/security\/2026\/04\/open-source-package-with-1-million-monthly-downloads-stole-user-credentials\/#comments\">Feedback<\/a><\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>Open supply software program with greater than 1 million month-to-month downloads was compromised after a risk actor exploited a vulnerability within the builders\u2019 account workflow that gave entry to its signing keys and different delicate data. On Friday, unknown attackers exploited the vulnerability to push a brand new model of element-data, a command-line interface that [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":14249,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[54],"tags":[483,2916,1636,8853,525,1717,1683,3598,207],"class_list":["post-14247","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","tag-credentials","tag-downloads","tag-million","tag-monthly","tag-open","tag-package","tag-source","tag-stole","tag-user"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/14247","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=14247"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/14247\/revisions"}],"predecessor-version":[{"id":14248,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/14247\/revisions\/14248"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/14249"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=14247"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=14247"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=14247"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-04-28 23:31:16 UTC -->