An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive ...
A single unauthenticated connection gives attackers a full shell; credential theft observed in under three minutes on honeypot servers.