PyPI supply chain compromise via GitHub Actions → elementary-data backdoored with .pth infostealer (exec on interpreter startup) (opens in new tab)
A massive supply chain attack hijacked the elementary-data PyPI package (v0.23.3) via GitHub Actions script injection. Learn how the infostealer works
Read the original article