Find notable cyber news and cases, enriched with sources, timelines, and signals.

Shai-Hulud PyPI supply-chain malware activity

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

The Shai-Hulud supply-chain malware compromised 19 PyPI packages, turning routine installs into secret-stealing execution and putting developer credentials at risk. The infected releases used a malicious `*-setup.pth` startup hook and obfuscated `_index.js` payload to trigger Python-driven execution. The activity spread through hundreds of thousands of downloads and targeted GitHub tokens, cloud credentials, SSH keys, and other development secrets.

Related Happenings

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

GitHub actions/checkout blocks fork pull request checkouts by default in privileged workflows

Security Tool/Service
H score11 First: 23.06.2026 17:22 Last: 23.06.2026 17:22 Sources 1

About this happening: GitHub's actions/checkout now refuses common pwn request patterns by default, cutting the risk of attacker-controlled code execution in privileged GitHub Actions workf...

Atomic-lockfile rootkit-infostealer distribution through AUR packages

Malware Activity
H score3 First: 12.06.2026 20:03 Last: 12.06.2026 20:03 Sources 1

About this happening: AUR packages are distributing the atomic-lockfile Linux rootkit and infostealer through compromised build scripts, with more than 400 packages reported and the o...

AUR package-hijacking campaign delivering atomic-lockfile

Campaign
H score11 First: 12.06.2026 20:03 Last: 12.06.2026 20:03 Sources 1

About this happening: AUR package-hijacking campaign is abusing more than 400 compromised Arch User Repository (AUR) packages to deliver atomic-lockfile, turning the AUR build path...

Miasma supply-chain malware activity

Malware Activity
H score34 First: 10.06.2026 23:27 Last: 10.06.2026 23:27 Sources 1

About this happening: The Miasma malware activity is enabling supply-chain compromise by stealing build environment and cloud credentials, then using them to poison legitimate packages...

Timeline

  1. 08.06.2026 23:41 2 articles · 1mo ago

    Shai-Hulud compromise hits 19 PyPI packages and steals developer secrets

    Initial Disclosure

    Socket identified a Shai-Hulud supply-chain compromise of 19 PyPI packages, spread across 37 malicious releases, that used a malicious `*-setup.pth` startup hook and an obfuscated `_index.js` payload to trigger Python-driven Bun execution and steal developer secrets from developer and CI/CD environments.

    Show sources