Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers

2026-04-28T20:52:04Zaedb9678df421fa67628826e0bd9192339b4d623dd92f785f11dd176915fd7c0
PyPIbackdoorcloud-credentialscredential-theftcryptominingdbtgithub-actionsincident-responsemalicious-packagepythonqinglongrceremediationscript-injectionssh-keyssupply-chain

What happened

Multiple Snyk posts describe active supply-chain and remote-exploit incidents. A malicious release of the elementary-data Python CLI (v0.23.3) was published after attackers exploited a GitHub Actions script-injection vulnerability; the package included a credential-stealing backdoor that targeted dbt profiles, cloud provider keys, and SSH secrets from data engineering environments. Separately, Qinglong task scheduler authentication-bypass RCEs (CVE-2026-3965, CVE-2026-4047) were exploited in the wild to deploy cryptomining malware. Operators should treat these as high-priority: revoke and roll

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
aedb9678df421fa67628826e0bd9192339b4d623dd92f785f11dd176915fd7c0
Enrichment time
2026-04-28T20:52:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers · Baitaphish