lightning PyPI Compromise: A Bun-Based Credential Stealer in Python

2026-05-01T08:52:12Z1af1f0ec32eaaf1cd002224b6f9ae2250316678651ea274388646190cb55463a
CVE-2026-40478advisorybackdoorbuncloud-credentialscredential-stealercredential-theftdbtdependency-auditgithub-actionsiocnpmpatchingpypirotate-keyssapscript-injectionssh-keyssupply-chaintemplate-injectionthymeleaf

What happened

Multiple high-impact supply-chain incidents reported by Snyk in late April 2026: malicious PyPI releases (lightning and elementary-data) and a Bun-based credential stealer affecting npm SAP ecosystem packages (Mini Shai-Hulud). The PyPI releases run credential‑stealing payloads on import, targeting cloud provider keys, dbt profiles, and SSH secrets; the elementary-data compromise was enabled via a GitHub Actions script-injection. Also published: CVE-2026-40478 (Thymeleaf template injection, CVSS 9.1) — patch to 3.1.4+ and audit dynamic template expressions. Immediate mitigations: remove/update

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
1af1f0ec32eaaf1cd002224b6f9ae2250316678651ea274388646190cb55463a
Enrichment time
2026-05-01T08:52:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.