lightning PyPI Compromise: A Bun-Based Credential Stealer in Python
2026-05-08T20:52:04Z•dfbd6ad1e94787d35c1d952ac6c69c5827a003890a448c0b6252a44e0e316dbd
BunCVE-2026-40478GitHub-ActionsIOCsPyPISSHSnyk-advisoryThymeleafcloud-credentialscredential-stealercredential-theftdbtmalicious-releasenpmpatchingrotationsupply-chaintemplate-injection
What happened
Multiple Snyk reports detail active supply‑chain attacks and a high‑severity template injection: (1) A malicious release of the lightning PyPI package included a Bun‑based credential stealer that runs on import; (2) a related Bun‑based stealer (self‑branded “Mini Shai‑Hulud”) compromised several npm packages in the SAP ecosystem (cap-js, mbt); (3) a malicious release of the elementary-data PyPI CLI (v0.23.3) — created via a GitHub Actions script‑injection — exfiltrated dbt profiles, cloud provider keys, and SSH secrets; and (4) a Thymeleaf template injection (CVE-2026-40478, CVSS 9.1) requires
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- dfbd6ad1e94787d35c1d952ac6c69c5827a003890a448c0b6252a44e0e316dbd
- Enrichment time
- 2026-05-08T20:52:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.