Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

0
Medium
Malware
Published: Mon Jun 08 2026 (06/08/2026, 20:41:35 UTC)
Source: Bleeping Computer

Description

Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal developer secrets. [...]

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/08/2026, 20:48:42 UTC

Technical Analysis

Hackers compromised 19 PyPI packages, primarily bioinformatics tools, injecting malicious code that executes upon Python startup via a .pth file. This code downloads the Bun JavaScript runtime to execute an obfuscated JavaScript payload that exfiltrates developer secrets such as GitHub tokens, cloud credentials, SSH keys, and configuration files. The malware uses evasion techniques including locale checks and security tool detection, and establishes persistence through systemd services and LaunchAgents. Data exfiltration occurs mainly through automatically created GitHub repositories via GitHub Actions, with a secondary HTTPS channel mimicking a legitimate API endpoint. This attack is linked to the broader Shai-Hulud campaign, which has compromised hundreds of open-source packages across ecosystems. Detection involves monitoring for Python packages with executable .pth hooks and Bun runtime downloads. The attack compromises software development workflows to propagate malware and steal sensitive secrets.

Potential Impact

The attack compromises developer workstations and CI/CD environments by stealing a broad range of sensitive credentials and secrets, including GitHub tokens, cloud service credentials (AWS, GCP, Azure), SSH keys, Docker credentials, and configuration files. This can lead to unauthorized access to source code repositories, cloud infrastructure, and other critical development and deployment resources. The persistence mechanisms and evasion techniques increase the difficulty of detection and removal. The widespread downloads of the affected packages imply a significant exposure risk to the developer community relying on these PyPI packages.

Mitigation Recommendations

There is no explicit patch available for the compromised packages; remediation involves removing the affected packages and restoring environments from safe backups. Organizations should immediately rotate all potentially exposed secrets, including tokens, keys, and credentials. Defenders should monitor for Python packages containing executable .pth startup hooks, unexpected downloads of the Bun JavaScript runtime from GitHub, and process chains where Python launches Bun to execute the malicious JavaScript payload. Investigate and remediate persistence mechanisms such as systemd services on Linux and LaunchAgents on macOS. Follow vendor or security researcher advisories for updates on affected packages and further guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/new-shai-hulud-attack-trojanizes-19-science-focused-pypi-packages/","fetched":true,"fetchedAt":"2026-06-08T20:48:35.710Z","wordCount":749}

Threat ID: 6a272aa3e29bf47b50938f4b

Added to database: 6/8/2026, 8:48:35 PM

Last enriched: 6/8/2026, 8:48:42 PM

Last updated: 6/9/2026, 4:58:03 AM

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses