lightning PyPI Compromise: A Bun-Based Credential Stealer in Python

2026-05-07T08:52:07Z2dc9669090e92a68016143ee2eb55e791b5fa21ff2b3210d5246a3ad9f0846df
BunCI/CDCVE-2026-40478GitHub ActionsIOCsPyPISSHSnyk-advisoryThymeleafcloud‑credentialscredential‑stealerdbtnpmpackage‑compromisesupply-chaintemplate‑injection

What happened

Snyk published multiple advisories (Apr 27–30, 2026) about active supply‑chain compromises and a high‑severity template injection: 1) Several PyPI and npm packages were maliciously published/distributed embedding a Bun‑based credential stealer (notably the lightning PyPI package and the "Mini Shai‑Hulud" compromises of SAP ecosystem npm packages such as @cap-js and mbt). 2) A malicious elementary-data PyPI release (v0.23.3) abused a GitHub Actions script injection to backdoor a Python CLI and exfiltrate dbt profiles, cloud provider keys, SSH secrets and other credentials. 3) A separate high‑sc

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
2dc9669090e92a68016143ee2eb55e791b5fa21ff2b3210d5246a3ad9f0846df
Enrichment time
2026-05-07T08:52:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.