<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/elementary-data-compromised-on-pypi-and-ghcr-forged-release-pushed-via-github-actions-script-inject-tue3awadq" -->

---
title: elementary-data Compromised on PyPI and GHCR: Forged...
description: A malicious version of the elementary-data Python package (0.23.3) was published to PyPI on April 24, 2026, via a GitHub Actions script injection attack. The...
canonical: https://daily.dev/posts/elementary-data-compromised-on-pypi-and-ghcr-forged-release-pushed-via-github-actions-script-inject-tue3awadq
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub Actions Script Injection | daily.dev
og:description: A malicious version of the elementary-data Python package (0.23.3) was published to PyPI on April 24, 2026, via a GitHub Actions script injection attack. The...
og:url: https://daily.dev/posts/elementary-data-compromised-on-pypi-and-ghcr-forged-release-pushed-via-github-actions-script-inject-tue3awadq
og:image: https://api.daily.dev/og/posts/tUE3awadQ.png
og:image:alt: elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub Actions Script Injection
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub Actions Script Injection

**[StepSecurity](https://daily.dev/sources/stepsecurity)** · 4 min read · 0 upvotes · 0 comments

## Summary

A malicious version of the elementary-data Python package (0.23.3) was published to PyPI on April 24, 2026, via a GitHub Actions script injection attack. The attacker exploited a vulnerability in the project's own CI workflow, used the GITHUB_TOKEN to forge a signed release commit, and triggered the legitimate publishing pipeline — without touching the main branch. The compromised release includes a .pth file that executes a three-stage credential-stealing payload on every Python invocation. The same workflow also pushed a trojaned multi-arch Docker image to GHCR tagged as both 0.23.3 and latest. The payload harvests SSH keys, cloud credentials (AWS, GCP, Azure), Kubernetes configs, .env files, crypto wallet keys, and more, exfiltrating everything to an attacker-controlled endpoint.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.stepsecurity.io/blog/elementary-data-compromised-on-pypi-and-ghcr-forged-release-pushed-via-github-actions-script-injection>

## Similar posts on daily.dev

- [PyPI package with 1.1M monthly downloads hacked to push infostealer](https://daily.dev/posts/pypi-package-with-1-1m-monthly-downloads-hacked-to-push-infostealer-rlyztwgm9) · BleepingComputer · 1 upvotes · 0 comments
- [Hackers Hijacked a GitHub Actions Workflow to Push Malicious Code to PyPI](https://daily.dev/posts/hackers-hijacked-a-github-actions-workflow-to-push-malicious-code-to-pypi-sxmpfdzik) · It's Foss · 0 upvotes · 0 comments
- [Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers](https://daily.dev/posts/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers-shmaxcjof) · Snyk · 0 upvotes · 0 comments
- [Open source package with 1 million monthly downloads stole user credentials](https://daily.dev/posts/open-source-package-with-1-million-monthly-downloads-stole-user-credentials-bunn9pjr7) · Ars Technica · 6 upvotes · 0 comments
- [Massive PyPI Supply Chain Attack Harvests Cloud Credentials via Python Startup Hooks](https://daily.dev/posts/massive-pypi-supply-chain-attack-harvests-cloud-credentials-via-python-startup-hooks-pbx2b1ksk) · Orca Security Blog · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#python](https://daily.dev/tags/python), [#github-actions](https://daily.dev/tags/github-actions)

[View this post on daily.dev](https://daily.dev/posts/elementary-data-compromised-on-pypi-and-ghcr-forged-release-pushed-via-github-actions-script-inject-tue3awadq)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub Actions Script Injection","url":"https://daily.dev/posts/elementary-data-compromised-on-pypi-and-ghcr-forged-release-pushed-via-github-actions-script-inject-tue3awadq","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/elementary-data-compromised-on-pypi-and-ghcr-forged-release-pushed-via-github-actions-script-inject-tue3awadq"},"datePublished":"2026-04-25T08:56:54.529Z","dateModified":"2026-04-25T08:57:19.424Z","description":"A malicious version of the elementary-data Python package (0.23.3) was published to PyPI on April 24, 2026, via a GitHub Actions script injection attack. The...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/70330a008b5bf8f6e82aa1fb8f192614?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/70330a008b5bf8f6e82aa1fb8f192614?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"StepSecurity","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"StepSecurity","logo":"https://media.daily.dev/image/upload/s--vegWii-S--/f_auto,q_auto/v1774959924/logos/stepsecurity?_a=BAMAMiWQ0","url":"https://daily.dev/sources/stepsecurity"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/elementary-data-compromised-on-pypi-and-ghcr-forged-release-pushed-via-github-actions-script-inject-tue3awadq","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,python,github-actions","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"StepSecurity","item":"https://daily.dev/sources/stepsecurity"},{"@type":"ListItem","position":3,"name":"elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub Actions Script Injection"}]}
```

