lightning PyPI Compromise: A Bun-Based Credential Stealer in Python
CYBERSECURITY FEATURED ANALYSIS

lightning PyPI Compromise: A Bun-Based Credential Stealer in Python

SOURCE

Blog RSS Feed | Snyk

DATE

READ

1 min read

A malicious release of the lightning PyPI package ships a credential-stealing Bun payload that runs on import. Snyk has a live advisory. Here’s what’s in the package, what to rotate, and how the payload …

A malicious release of the lightning PyPI package ships a credential-stealing Bun payload that runs on import. Snyk has a live advisory. Here’s what’s in the package, what to rotate, and how the payload pattern connects to the Mini Shai-Hulud npm campaign one day earlier.