Skip to content
Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Ex-BioWare Dev Explains Why He Thinks Dragon Age Is Basically Dead

    July 27, 2026

    Crunchyroll Is Missing Anime’s Rarest Classics, And This Free Streaming Service Is Here To Help

    July 27, 2026

    Australia’s best-selling PHEVs halfway through 2026

    July 27, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»Open source package with 1 million monthly downloads stole user credentials
    Open source package with 1 million monthly downloads stole user credentials
    Tech Reviews

    Open source package with 1 million monthly downloads stole user credentials

    gvfx00@gmail.comBy gvfx00@gmail.comApril 28, 2026No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    The developers are urging all developers who installed version 0.23.3 to take the following steps immediately:

    1. Check your installed version:

    pip show elementary-data | grep Version

    2. If the version is 0.23.3, uninstall it and replace it with the safe version:

    pip uninstall elementary-data

    pip install elementary-data==0.23.4

    In your requirements and lockfiles, pin explicitly to elementary-data==0.23.4.

    3. Delete your cache files to avoid any artifacts.

    4. Check for the malware’s marker file on any machine where the CLI may have run: If this file is present, the payload executed on that machine.

    macOS / Linux: /tmp/.trinny-security-update

    Windows: %TEMP%\\.trinny-security-update

    5. Rotate any credentials that were accessible from the environment where 0.23.3 ran – dbt profiles, warehouse credentials, cloud provider keys, API tokens, SSH keys, and the contents of any .env files. CI/CD runners are especially exposed because they typically have broad sets of secrets mounted at runtime.

    6. Contact your security team to hunt for unauthorized usage of exposed credentials. The relevant IOCs are at the bottom of this post.

    Over the past decade, supply-chain attacks on open source repositories have become increasingly common. In some cases, they have achieved a chain of compromises as the malicious package leads to breaches of users and, from there, breaches resulting from the compromise of the users’ environments.

    HD Moore, a hacker with more than four decades of experience and the founder and CEO of runZero, said that user-developed repository workflows, such as GitHub actions, are notorious for hosting vulnerabilities.

    It’s a “a major problem for open source projects with open repos,” he said. “It’s really hard to not accidentally create dangerous workflows that can be exploited by an attacker’s pull request.”

    He said this package can be used to check for such vulnerabilities.

    Table of Contents

    Toggle
      • Related posts:
    • AI chatbots are now integrated 'into the full texture of human life,' Microsoft study claims
    • Fable Dodges GTA VI With Another Delay
    • Critics scoff after Microsoft warns AI feature can infect machines and pilfer data

    Related posts:

    Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs

    Save up to 60 percent on Star Wars, Disney, Harry Potter and more during the biggest holiday sale

    AWS is building a new high-speed subsea internet cable to connect the US and Ireland

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article‘Pizza Tower’, ‘Castlevania Dominus Collection’, Plus Today’s Other Releases and Sales – TouchArcade
    Next Article GPT 5.5 vs Opus 4.7: Which is the Best AI Model Today?
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    Can’t find the Chrome extension you want? I used Claude to make me two personalized ones — and they’re working flawlessly

    July 27, 2026
    Tech Reviews

    Is Your Phone Actually Worth It? Share Your Thoughts

    July 27, 2026
    Tech Reviews

    TP-Link Tapo C660 Kit review: a bang-for-your-buck 4K security camera with local storage

    July 27, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025212 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025134 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 2025102 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025212 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025134 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 2025102 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.