New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
ID: 91cfda69-2c2f-5c60-bbaa-7cfc01aa84be
STIX ID: report--91cfda69-2c2f-5c60-bbaa-7cfc01aa84be
Feed Name: Bleeping Computer
Researchers discovered a Shai-Hulud supply-chain campaign that trojanized 19 PyPI packages (37 malicious releases) using '*-setup.pth' startup hooks that trigger an obfuscated JavaScript payload via the Bun runtime; the malware harvests extensive developer and CI secrets (tokens, cloud credentials, SSH keys, config files), persists via systemd/LaunchAgents and CI artifacts, employs locale and tooling evasion checks, and exfiltrates stolen data through auto-created GitHub repositories and direct HTTPS endpoints. Organizations are advised to rotate secrets, restore from safe backups, and detect indicators such as executable .pth hooks, unexpected Bun downloads, and Python→Bun→_index.js process chains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
