PyPI publishing tokens and secrets stolen in GhostAction campaign
Data Leak
Summary
Hide ▲
Show ▼
A GhostAction supply-chain compromise exposed PyPI publishing tokens and other secrets, creating immediate risk for maintainer credentials and API access. PyPI invalidated the affected tokens after the theft was confirmed, and investigators said the tokens did not appear to have been used to publish malware. The stolen material spanned npm, DockerHub, GitHub, Cloudflare, AWS, and database credentials.
Related Happenings
Mini Shai-Hulud supply-chain campaign targeting npm and PyPI
Campaign
H score45
First: 12.05.2026 17:45
Last: 12.05.2026 17:45
Sources 1
About this happening:
The Mini Shai-Hulud supply-chain campaign linked to TeamPCP expanded into downstream victim reporting, including Grafana Labs. Grafana said its GitHub environmen...
Mini Shai-Hulud supply-chain campaign targeting npm and PyPI
CampaignAbout this happening: The Mini Shai-Hulud supply-chain campaign linked to TeamPCP expanded into downstream victim reporting, including Grafana Labs. Grafana said its GitHub environmen...
Latest development: 21.05.2026 11:00
Grafana Labs said its GitHub environment was accessed and its codebase downloaded, with additional internal operational information taken from GitHub repositories, after compromise linked to the Mini Shai-Hulud campaign and TanStack npm packages. Grafana said it first spotted malicious activity on May 11, discovered the unauthorized download on May 17, and after contact from the ransom gang rotated automation tokens, enabled enhanced monitoring, audited commits since the May 11 incident, and hardened its GitHub security posture, while saying there is no indication customer production systems or operations were compromised.
Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials
Campaign
H score56
First: 12.05.2026 14:29
Last: 12.05.2026 14:29
Sources 1
About this happening:
GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...
Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials
CampaignAbout this happening: GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...
Mini Shai-Hulud npm supply-chain malware wave
Malware Activity
H score68
First: 12.05.2026 14:07
Last: 12.05.2026 14:07
Sources 1
About this happening:
The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...
Mini Shai-Hulud npm supply-chain malware wave
Malware ActivityAbout this happening: The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...
Latest development: 09.06.2026 18:42
On June 5, Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub after concerns about potential malicious content tied to the Miasma/Shai-Hulud supply-chain campaign. The action disrupted continuous integration pipelines and broke workflows that depended on Azure/functions-action, while Microsoft said it temporarily removed some repositories during its investigation.
Lightning PyPI router_runtime.js credential-stealing payload
Malware Activity
H score29
First: 30.04.2026 19:31
Last: 30.04.2026 19:31
Sources 1
About this happening:
The Lightning PyPI package was pushed in malicious versions 2.6.2 and 2.6.3 on April 30, 2026, turning a normal install into credential theft for developer and C...
Lightning PyPI router_runtime.js credential-stealing payload
Malware ActivityAbout this happening: The Lightning PyPI package was pushed in malicious versions 2.6.2 and 2.6.3 on April 30, 2026, turning a normal install into credential theft for developer and C...
Latest development: 04.05.2026 20:15
Microsoft Threat Intelligence says Defender detected and prevented the malicious `lightning==2.6.3` routine in customer environments, notified the Lightning maintainer, and warned that users who ran `import lightning` may need to rotate exposed secrets, keys, and tokens.
Mini Shai-Hulud SAP-related npm supply-chain campaign
Campaign
H score45
First: 29.04.2026 19:26
Last: 29.04.2026 19:26
Sources 1
About this happening:
A new Mini Shai-Hulud supply-chain campaign is targeting SAP-related npm packages, putting developer and CI/CD environments at risk of credential theft and malicious p...
Mini Shai-Hulud SAP-related npm supply-chain campaign
CampaignAbout this happening: A new Mini Shai-Hulud supply-chain campaign is targeting SAP-related npm packages, putting developer and CI/CD environments at risk of credential theft and malicious p...
Latest development: 12.05.2026 11:50
Mini Shai-Hulud expands beyond the original SAP-related npm packages to compromise TanStack, UiPath, Mistral AI, OpenSearch, Guardrails AI, and DraftLab packages across npm and PyPI, with malicious payloads using router_init.js, GitHub Actions abuse, and exfiltration to filev2.getsession[.]org, api.masscan[.]cloud, or attacker-controlled GitHub repositories.
Timeline
-
18.09.2025 16:09 1 articles · 10mo ago
GitGuardian reports PyPI token theft
Initial DisclosureA GitGuardian employee reported malicious GitHub Actions workflows, including one in FastUUID, that tried to exfiltrate PyPI tokens to a remote server.
Show sources
- PyPI invalidates tokens stolen in GhostAction supply chain attack — www.bleepingcomputer.com — 18.09.2025 16:09
-
18.09.2025 16:09 1 articles · 10mo ago
PyPI response is delayed until September 10
Detection Ioc UpdateA GitGuardian researcher's follow-up email with additional findings landed in spam, delaying PyPI Security's incident response until September 10 after the malicious GitHub Actions secret-exfiltration activity had been reported.
Show sources
- PyPI invalidates tokens stolen in GhostAction supply chain attack — www.bleepingcomputer.com — 18.09.2025 16:09
-
18.09.2025 16:09 1 articles · 10mo ago
PyPI invalidates stolen tokens and advises Trusted Publishers
Mitigation Patch UpdateAfter confirming that no PyPI accounts had been compromised, PyPI's Mike Fiedler contacted maintainers of affected projects on September 15, told them their tokens had been invalidated, and recommended replacing long-lived GitHub Actions tokens with short-lived Trusted Publishers tokens.
Show sources
- PyPI invalidates tokens stolen in GhostAction supply chain attack — www.bleepingcomputer.com — 18.09.2025 16:09
-
18.09.2025 16:09 2 articles · 10mo ago
PyPI says stolen tokens were not used on PyPI
Victim Impact UpdateThe Python Software Foundation said it had invalidated all PyPI tokens stolen in the GhostAction supply-chain attack and found no evidence that the threat actors used them to publish malware on PyPI.
Show sources
- PyPI invalidates tokens stolen in GhostAction supply chain attack — www.bleepingcomputer.com — 18.09.2025 16:09
- PyPI invalidates tokens stolen in GhostAction supply chain attack — www.bleepingcomputer.com — 18.09.2025 16:09