PyPI package with 1.1M monthly downloads hacked to push infostealer
PyPI package with 1.1M monthly downloads hacked to push infostealer
Mon Apr 27 2026
Malware
Open Source
Software
www.bleepingcomputer.com
An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive developer data and cryptocurrency wallets. [...]