Security Feed
  1. Archives

Apr 27 2026 PyPI package with 1.1M monthly downloads hacked to push infostealer

Source

An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive developer data and cryptocurrency wallets. [...]

Posted by Bill Toulas on Mon 27 April 2026 in BleepingComputer.

Tags: Security.

Categories

  1. Ars Technica
  2. AWS Security
  3. BleepingComputer
  4. Brian Krebs
  5. Bruce Schneier
  6. GCP Security
  7. Google Project Zero
  8. The Daily Swig
  9. The Guardian
  10. The Register
  11. Threatpost

Tag cloud

  • Security
  • Uncategorized
  • Security, Identity, & Compliance
  • Microsoft
  • Biz & IT
  • Security Blog
  • AI
  • Security & Identity
  • CryptoCurrency
  • Google
  • Announcements
  • Artificial Intelligence
  • Foundational (100)
  • Legal
  • A Little Sunshine
  • Privacy
  • Apple
  • Mobile
  • squid
  • hacking
  • Intermediate (200)
  • LLM
  • Advanced (300)
  • Technical How-to
  • The Coming Storm

Security Feed. Powered by Pelican and m.css. Code is available on GitLab.