


Perceptive Security
SOC/SIEM Consultancy

elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub Actions Script Injection
Published:
25 april 2026 om 08:55:08
Alert date:
25 april 2026 om 09:00:44
Source:
stepsecurity.io
Supply Chain & Dependencies
A supply chain attack compromised the elementary-data Python package, with malicious version 0.23.3 published to PyPI through GitHub Actions script injection. The attack also pushed compromised container images to GitHub Container Registry. The malicious package was still listed as the latest release at the time of reporting, affecting both PyPI distribution and container deployments. This represents an active supply chain compromise targeting Python developers and containerized environments.
Technical details
Mitigation steps:
Affected products:
elementary-data
PyPI
GitHub Container Registry
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
