A supply-chain attack dubbed 'Shai-Hulud' has compromised 19 PyPI packages — many popular bioinformatics tools like Dynamo, Spateo, and Napari-UFISH — across 37 malicious releases. The attack was discovered by Socket and works by injecting a malicious .pth file and obfuscated JavaScript payload into package wheels. Simply starting Python triggers the .pth file, which downloads the Bun JavaScript runtime from GitHub to execute the payload. The malware targets a wide range of developer secrets including GitHub tokens, cloud credentials (AWS, GCP, Azure), SSH keys, Docker credentials, and CI/CD secrets. Exfiltration uses auto-created GitHub repositories and a camouflaged HTTPS endpoint mimicking Anthropic's API. Persistence is achieved via systemd on Linux and LaunchAgents on macOS. This campaign is linked to a broader Shai-Hulud operation now tracking 453 malicious artifacts. Affected organizations are advised to rotate all secrets and restore from clean backups.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
256 Impressions