lightning PyPI Compromise: A Bun-Based Credential Stealer in Python
2026-05-01T08:52:12Z•1af1f0ec32eaaf1cd002224b6f9ae2250316678651ea274388646190cb55463a
CVE-2026-40478advisorybackdoorbuncloud-credentialscredential-stealercredential-theftdbtdependency-auditgithub-actionsiocnpmpatchingpypirotate-keyssapscript-injectionssh-keyssupply-chaintemplate-injectionthymeleaf
What happened
Multiple high-impact supply-chain incidents reported by Snyk in late April 2026: malicious PyPI releases (lightning and elementary-data) and a Bun-based credential stealer affecting npm SAP ecosystem packages (Mini Shai-Hulud). The PyPI releases run credential‑stealing payloads on import, targeting cloud provider keys, dbt profiles, and SSH secrets; the elementary-data compromise was enabled via a GitHub Actions script-injection. Also published: CVE-2026-40478 (Thymeleaf template injection, CVSS 9.1) — patch to 3.1.4+ and audit dynamic template expressions. Immediate mitigations: remove/update
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- 1af1f0ec32eaaf1cd002224b6f9ae2250316678651ea274388646190cb55463a
- Enrichment time
- 2026-05-01T08:52:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.