MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Elementary Data release pipeline compromised to publish malicious PyPI and Docker artifacts

On 24 April 2026, an attacker exploited a script-injection vulnerability in an Elementary Data GitHub Actions workflow and used the compromised release process to publish malicious elementary-data version 0.23.3 to PyPI and a corresponding malicious Docker image. Elementary confirmed that the forged release contained malicious code and warned users who executed it to assume that credentials accessible from their environments may have been exposed. The company removed the affected artifacts, rotated credentials and released a clean replacement. The poisoning of official package and container distribution channels constitutes a direct software-supply-chain data-integrity impact.

69

Estimated severity

69 / 100

92

Source reliability

92 / 100

Approximate Date

24/04/2026

Targeted Company

ELEMENTARY DATA

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Israel

ISR

Other Affected Countries

No other affected countries reported

Target country

Israel

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseMalwareExploitation of vulnerability

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.