A widely used PyPI package was recently compromised through a malicious update The attack leveraged a GitHub Actions workflow ...