lightning PyPI Compromise: A Bun-Based Credential Stealer in Python

2026-05-08T20:52:04Zdfbd6ad1e94787d35c1d952ac6c69c5827a003890a448c0b6252a44e0e316dbd
BunCVE-2026-40478GitHub-ActionsIOCsPyPISSHSnyk-advisoryThymeleafcloud-credentialscredential-stealercredential-theftdbtmalicious-releasenpmpatchingrotationsupply-chaintemplate-injection

What happened

Multiple Snyk reports detail active supply‑chain attacks and a high‑severity template injection: (1) A malicious release of the lightning PyPI package included a Bun‑based credential stealer that runs on import; (2) a related Bun‑based stealer (self‑branded “Mini Shai‑Hulud”) compromised several npm packages in the SAP ecosystem (cap-js, mbt); (3) a malicious release of the elementary-data PyPI CLI (v0.23.3) — created via a GitHub Actions script‑injection — exfiltrated dbt profiles, cloud provider keys, and SSH secrets; and (4) a Thymeleaf template injection (CVE-2026-40478, CVSS 9.1) requires

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
dfbd6ad1e94787d35c1d952ac6c69c5827a003890a448c0b6252a44e0e316dbd
Enrichment time
2026-05-08T20:52:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.