lightning PyPI Compromise: A Bun-Based Credential Stealer in Python
2026-05-02T08:52:02Z•d93b84ced1f18ad70b59303a44f550e06da7d6b010e0afe2d5c28bb5d8f49375
BunCI/CD compromiseCVE-2026-40478GitHub ActionsIOCsPyPISSH keysSnyk advisoryThymeleafcloud‑credentialscredential‑stealerdbtnpmremediationrotate credentialssupply-chaintemplate‑injection
What happened
Multiple Snyk advisories describe active supply‑chain malware and a high‑severity template injection: (1) A malicious release of the lightning PyPI package contains a Bun‑based credential stealer that executes on import; (2) a related “Mini Shai‑Hulud” Bun stealer compromised several SAP‑ecosystem npm packages (cap‑js, mbt); (3) a compromised release of the elementary‑data PyPI CLI (v0.23.3) — injected via a GitHub Actions script compromise — steals dbt profiles, cloud provider keys and SSH secrets; and (4) a conditional Thymeleaf template injection (CVE‑2026‑40478, CVSS 9.1) requires unsafe/d
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- d93b84ced1f18ad70b59303a44f550e06da7d6b010e0afe2d5c28bb5d8f49375
- Enrichment time
- 2026-05-02T08:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.