lightning PyPI Compromise: A Bun-Based Credential Stealer in Python

2026-05-02T08:52:02Zd93b84ced1f18ad70b59303a44f550e06da7d6b010e0afe2d5c28bb5d8f49375
BunCI/CD compromiseCVE-2026-40478GitHub ActionsIOCsPyPISSH keysSnyk advisoryThymeleafcloud‑credentialscredential‑stealerdbtnpmremediationrotate credentialssupply-chaintemplate‑injection

What happened

Multiple Snyk advisories describe active supply‑chain malware and a high‑severity template injection: (1) A malicious release of the lightning PyPI package contains a Bun‑based credential stealer that executes on import; (2) a related “Mini Shai‑Hulud” Bun stealer compromised several SAP‑ecosystem npm packages (cap‑js, mbt); (3) a compromised release of the elementary‑data PyPI CLI (v0.23.3) — injected via a GitHub Actions script compromise — steals dbt profiles, cloud provider keys and SSH secrets; and (4) a conditional Thymeleaf template injection (CVE‑2026‑40478, CVSS 9.1) requires unsafe/d

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
d93b84ced1f18ad70b59303a44f550e06da7d6b010e0afe2d5c28bb5d8f49375
Enrichment time
2026-05-02T08:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.