lightning PyPI Compromise: A Bun-Based Credential Stealer in Python
2026-05-07T08:52:07Z•2dc9669090e92a68016143ee2eb55e791b5fa21ff2b3210d5246a3ad9f0846df
BunCI/CDCVE-2026-40478GitHub ActionsIOCsPyPISSHSnyk-advisoryThymeleafcloud‑credentialscredential‑stealerdbtnpmpackage‑compromisesupply-chaintemplate‑injection
What happened
Snyk published multiple advisories (Apr 27–30, 2026) about active supply‑chain compromises and a high‑severity template injection: 1) Several PyPI and npm packages were maliciously published/distributed embedding a Bun‑based credential stealer (notably the lightning PyPI package and the "Mini Shai‑Hulud" compromises of SAP ecosystem npm packages such as @cap-js and mbt). 2) A malicious elementary-data PyPI release (v0.23.3) abused a GitHub Actions script injection to backdoor a Python CLI and exfiltrate dbt profiles, cloud provider keys, SSH secrets and other credentials. 3) A separate high‑sc
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- 2dc9669090e92a68016143ee2eb55e791b5fa21ff2b3210d5246a3ad9f0846df
- Enrichment time
- 2026-05-07T08:52:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.