#Opensource package with 1 million monthly downloads stole user credentials
… #compromised after a threat actor #exploited a #vulnerability in the developers’ account workflow that gave access to its signing keys and other sensitive information
On Friday, unknown attackers exploited the vulnerability to push a new version of #elementData, a command-line interface that helps users monitor performance and anomalies in machine-learning systems.
#security #privacy #ml









