Open-source supply-chain attack steals credentials via poisoned package

TL;DR
Attackers exploited a GitHub Actions workflow to gain access to signing keys and credentials, publishing a malicious element-data 0.23.3 package that scanned environments for sensitive data; the package was removed within ~12 hours, credentials rotated, and users are urged to upgrade to 0.23.4, purge caches, and rotate any exposed secrets.
Want the full story? Read the original reporting
Read on Ars Technica