PyPI package with 1.1M monthly downloads hacked to push infostealer
From BleepingComputer to All on Mon Apr 27 12:14:34 2026
An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive developer data and cryptocurrency wallets. [...]