lightning PyPI Compromise: A Bun-Based Credential Stealer in Python
2026-05-08T08:52:05Z•915b4db5bedace44cdc42d6ce3e0d41e8f2be0b734f88265759b77d9e87514e3
BunCVE-2026-40478PyPISnykThymeleafbackdoorcredential-theftgithub-actionsnpmpatchrotate-credentialssupply-chain
What happened
Multiple active supply-chain incidents and a high‑severity template injection were reported by Snyk. Malicious PyPI releases include 'lightning' (a Bun-based credential stealer that executes on import) and 'elementary-data' (v0.23.3) — the latter introduced via a GitHub Actions script-injection and steals cloud provider keys, dbt profiles, and SSH secrets. A Bun-based stealer dubbed “Mini Shai‑Hulud” compromised several npm SAP ecosystem packages (including @cap-js and mbt). Separately, Thymeleaf template injection CVE‑2026‑40478 (CVSS 9.1) is exploitable when applications evaluate untrusted/d
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- 915b4db5bedace44cdc42d6ce3e0d41e8f2be0b734f88265759b77d9e87514e3
- Enrichment time
- 2026-05-08T08:52:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.