Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers
2026-04-28T20:52:04Z•aedb9678df421fa67628826e0bd9192339b4d623dd92f785f11dd176915fd7c0
PyPIbackdoorcloud-credentialscredential-theftcryptominingdbtgithub-actionsincident-responsemalicious-packagepythonqinglongrceremediationscript-injectionssh-keyssupply-chain
What happened
Multiple Snyk posts describe active supply-chain and remote-exploit incidents. A malicious release of the elementary-data Python CLI (v0.23.3) was published after attackers exploited a GitHub Actions script-injection vulnerability; the package included a credential-stealing backdoor that targeted dbt profiles, cloud provider keys, and SSH secrets from data engineering environments. Separately, Qinglong task scheduler authentication-bypass RCEs (CVE-2026-3965, CVE-2026-4047) were exploited in the wild to deploy cryptomining malware. Operators should treat these as high-priority: revoke and roll
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- aedb9678df421fa67628826e0bd9192339b4d623dd92f785f11dd176915fd7c0
- Enrichment time
- 2026-04-28T20:52:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.