Israel
ISR
On 24 April 2026, an attacker exploited a script-injection vulnerability in an Elementary Data GitHub Actions workflow and used the compromised release process to publish malicious elementary-data version 0.23.3 to PyPI and a corresponding malicious Docker image. Elementary confirmed that the forged release contained malicious code and warned users who executed it to assume that credentials accessible from their environments may have been exposed. The company removed the affected artifacts, rotated credentials and released a clean replacement. The poisoning of official package and container distribution channels constitutes a direct software-supply-chain data-integrity impact.
Estimated severity
69 / 100
Source reliability
92 / 100
Approximate Date
24/04/2026
Targeted Company
ELEMENTARY DATA
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Israel
ISR
No other affected countries reported
Target country
Israel
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Please rotate your phone