Open Source Package with Over 1 Million Downloads Compromised, User Credentials Stolen

A widely-used open source package was compromised, leading to the theft of user credentials after a vulnerability was exploited.

3 min readTechnology

An open source software package, which boasts over a million downloads each month, fell victim to a security breach. Attackers took advantage of a flaw in the developers' account management process, allowing them to gain access to critical signing keys and other confidential data. On Friday, these malicious actors released a compromised version of element-data, a command-line tool designed for monitoring machine-learning system performance. This tainted version, labeled as 0.23.3, was capable of searching for sensitive information on users' systems, including API tokens, SSH keys, and cloud service credentials. The malicious update was available on the Python Package Index and Docker repositories but was removed within approximately 12 hours. Fortunately, other packages like Elementary Cloud and the Elementary dbt package remained unaffected. Developers have advised users who downloaded version 0.23.3 or the compromised Docker image to assume that their credentials may have been exposed.

Technology