
CYBERSECURITY
FEATURED ANALYSIS
lightning PyPI Compromise: A Bun-Based Credential Stealer in Python
SOURCE
Blog RSS Feed | Snyk
DATE
READ
1 min read
A malicious release of the lightning PyPI package ships a credential-stealing Bun payload that runs on import. Snyk has a live advisory. Here’s what’s in the package, what to rotate, and how the payload …
A malicious release of the lightning PyPI package ships a credential-stealing Bun payload that runs on import. Snyk has a live advisory. Here’s what’s in the package, what to rotate, and how the payload pattern connects to the Mini Shai-Hulud npm campaign one day earlier.