Attackers abused a script-injection flaw in the elementary-data project's GitHub Actions workflow to forge a signed 0.23.3 release and publish trojanized artifacts to both PyPI and GitHub Container Registry. The malicious package and matching container images used an elementary.pth file to execute automatically and deploy a multi-stage infostealer that targeted SSH keys, Git and developer credentials, AWS, GCP, and Azure secrets, Kubernetes and Docker data, CI/CD tokens, .env files, database credentials, shell histories, system information, and cryptocurrency wallet material. Researchers said the attacker exposed the repository GITHUB_TOKEN, created a forged commit and tag, and triggered the legitimate release pipeline without compromising maintainer accounts or altering the main branch.
Community member crisperik flagged the malicious release, after which maintainers removed the poisoned PyPI package and GHCR images, released clean version 0.23.4, and removed the vulnerable workflow for further review. Organizations that installed elementary-data 0.23.3 or pulled the affected container images were urged to uninstall and replace the package, clear caches, check for the malware marker file, rotate all accessible secrets, and rebuild or restore impacted developer and CI environments from a known safe state.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
The Elementary Python CLI project disclosed that version 0.23.3 was malicious and said attackers had compromised its GitHub Actions release workflow. The project also removed the vulnerable workflow and audited other workflows for similar script injection issues.
After the malicious 0.23.3 release was identified, maintainers published version 0.23.4 as a clean replacement and advised users to uninstall 0.23.3 and rotate exposed secrets. Multiple reports describe 0.23.4 as the safe version to pin and restore from.
On April 25, 2026, community members reported and confirmed the compromise, after which the Elementary team removed the malicious PyPI package and GHCR images. The incident was tied to exploitation of a GitHub Actions script injection flaw that exposed the repository's GITHUB_TOKEN and enabled a forged signed release.
On April 25, 2026, community member crisperik opened a GitHub issue warning that release 0.23.3 contained a Base64-encoded elementary.pth file that executed during installation. The report flagged the release as a likely supply-chain compromise.
A trojanized release of elementary-data version 0.23.3 was published to PyPI on April 24, 2026, and matching malicious container images were pushed to GitHub Container Registry under the 0.23.3 and latest tags. The forged release was produced through the project's legitimate release pipeline after abuse of a GitHub Actions workflow.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceitpro.com
Open sourcearstechnica.com
Open sourcebleepingcomputer.com
Open sourceelementary-data.com
Open sourcestepsecurity.io
Open sourceopennet.me
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.