Shai-Hulud Hades new variant attacks PyPI, using Python to Bun cross-runtime chains to steal credentials

robot
Abstract generation in progress
Mars Finance reports that, according to SlowMist, a new variant of Shai-Hulud Hades is attacking PyPI. The malicious package injects .pth files that automatically execute during Python startup and check if Bun is installed locally; if not, it downloads the official Bun binary from GitHub Releases, then executes multi-layer obfuscated JavaScript payloads designed to steal credentials from GitHub, npm, AWS, and cloud services. SlowMist states that this variant uses the same RSA public key and infrastructure as previous Shai-Hulud attacks and has capabilities including encrypted exfiltration, persistence, CI/CD injection, and GitHub Actions injection.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned