lightning PyPI Compromise: A Bun-Based Credential Stealer in Python

2026-05-10T08:52:05Z8d043aaae7254ecd80627c9b586c1058a94125201c3af9adc5b8196ec57e19fd
CVE-2026-40478atlassianbuncap-jscloud-credentialscredential-stealerdbtelementary-datagithub-actionsgitopsioCsjavascriptjirambtnpmpypipythonsapsnykssh-keyssupply-chainthymeleaf

What happened

The feed describes multiple active supply-chain incidents and one high-severity template-injection vulnerability in late April 2026. Two separate Bun-based credential-stealing campaigns impacted packages across ecosystems: a malicious lightning PyPI release (runs on import) and the “Mini Shai-Hulud” npm campaign that compromised SAP-related packages (cap-js, mbt). A malicious elementary-data PyPI release (v0.23.3) used a GitHub Actions script-injection to publish a backdoor targeting dbt profiles, cloud provider keys and SSH secrets. Also reported: Thymeleaf template injection CVE-2026-40478 (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
8d043aaae7254ecd80627c9b586c1058a94125201c3af9adc5b8196ec57e19fd
Enrichment time
2026-05-10T08:52:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.