lightning PyPI Compromise: A Bun-Based Credential Stealer in Python

2026-05-08T08:52:05Z915b4db5bedace44cdc42d6ce3e0d41e8f2be0b734f88265759b77d9e87514e3
BunCVE-2026-40478PyPISnykThymeleafbackdoorcredential-theftgithub-actionsnpmpatchrotate-credentialssupply-chain

What happened

Multiple active supply-chain incidents and a high‑severity template injection were reported by Snyk. Malicious PyPI releases include 'lightning' (a Bun-based credential stealer that executes on import) and 'elementary-data' (v0.23.3) — the latter introduced via a GitHub Actions script-injection and steals cloud provider keys, dbt profiles, and SSH secrets. A Bun-based stealer dubbed “Mini Shai‑Hulud” compromised several npm SAP ecosystem packages (including @cap-js and mbt). Separately, Thymeleaf template injection CVE‑2026‑40478 (CVSS 9.1) is exploitable when applications evaluate untrusted/d

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
915b4db5bedace44cdc42d6ce3e0d41e8f2be0b734f88265759b77d9e87514e3
Enrichment time
2026-05-08T08:52:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · lightning PyPI Compromise: A Bun-Based Credential Stealer in Python · Baitaphish