INCIDENT
OpenMatter - A popular Python package was compromised, exposing sensitive
A popular Python package was compromised, exposing sensitive data, highlighting the security risks in the agentic economy.
Updated: 3/25/2026
high Severity
Status: active
Description
This proves our core thesis at @OpenMatter_ The agentic economy cannot survive on software promises. A package with 97M monthly downloads was poisoned. A single pip install exfiltrated AWS creds, SSH keys, crypto wallets, & DB passwords. They were only stopped because it https://t.co/lK89WRt4lK
Impact
A popular Python package was compromised, exposing sensitive data, highlighting the security risks in the agentic economy.
Attack Vectors
- security