Malicious code has been implanted in the Python package elementary-data, which has 1.1 million downloads per month.

Elementary Data reported a compromise of GitHub Actions workflows, allowing attackers to publish the release of the elementary-data package version 0.23.3 in the PyPI directory and GitHub repository, which contained malicious code designed to steal sensitive information from user systems. This malicious release was also included in the official Docker image of the project. Last month, the elementary-data package was downloaded over 1.1 million times from the PyPI repository.

The malicious release was published on April 25 at 1:20 AM (MSK) and remained available for download for more than 11 hours (until 12:45 PM). The attack was carried out by submitting a pull request with a specially crafted comment that exploited a vulnerability in the automatically invoked GitHub Action handler. The attackers managed to execute shell commands in the continuous integration environment and extract the content of the GITHUB_TOKEN environment variable, which provides repository access. This token was used to create several branches in git and prepare the release.

The release published by the attackers included malicious code encoded in base64 format, which was activated during package installation. The malicious code scanned the system and sent sensitive data, such as SSH and SSL/TLS keys, environment variable contents, AWS, GCP, Azure, and K8s credentials, cryptocurrency wallet keys, database passwords, command interpreter history, configuration files from Git, CI/CD, package managers, and Docker.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster