logo

New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

ID: 91cfda69-2c2f-5c60-bbaa-7cfc01aa84be

STIX ID: report--91cfda69-2c2f-5c60-bbaa-7cfc01aa84be

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Bill Toulas

...
...

Researchers discovered a Shai-Hulud supply-chain campaign that trojanized 19 PyPI packages (37 malicious releases) using '*-setup.pth' startup hooks that trigger an obfuscated JavaScript payload via the Bun runtime; the malware harvests extensive developer and CI secrets (tokens, cloud credentials, SSH keys, config files), persists via systemd/LaunchAgents and CI artifacts, employs locale and tooling evasion checks, and exfiltrates stolen data through auto-created GitHub repositories and direct HTTPS endpoints. Organizations are advised to rotate secrets, restore from safe backups, and detect indicators such as executable .pth hooks, unexpected Bun downloads, and Python→Bun→_index.js process chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.