lightning PyPI Compromise: A Bun-Based Credential Stealer in Python

2026-05-07T20:52:16Zcf00cf004d1dabef6e10d15662cae896788b8a4a810fc8e9f5e0c571e7526d55
BunCVE-2026-40478GitHub ActionsIOCsMini Shai-HuludPyPISAPSnyk-advisoryThymeleafcap-jscloud-credentialscredential-stealerelementary-datalightningmbtnpmrotationsupply-chaintemplate-injection

What happened

Multiple Snyk blog advisories describe a string of high-impact supply‑chain incidents and a severe template‑injection vulnerability. Recent malicious PyPI releases (lightning and elementary-data) and a small npm campaign (“Mini Shai‑Hulud”) delivered Bun‑based credential‑stealers that run on import and exfiltrate cloud provider keys, dbt profiles, SSH secrets and other developer credentials; attackers used a GitHub Actions script injection to publish at least one malicious release. Separately, Thymeleaf template injection (CVE-2026-40478, CVSS 9.1) is critical when applications evaluate un‑san

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
cf00cf004d1dabef6e10d15662cae896788b8a4a810fc8e9f5e0c571e7526d55
Enrichment time
2026-05-07T20:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.