
- A widely used PyPI package was recently compromised through a malicious update
- The attack leveraged a GitHub Actions workflow to push infostealer code into a release
- Maintainers quickly issued a clean version, rotated credentials, and began an external investigation
A popular Python Package Index (PyPI) package has been compromised and used to deliver malware to its users, experts have warned.