New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
Hackers compromised 19 science-focused packages on PyPI in a Shai-Hulud supply-chain attack. The trojanized packages were collectively downloaded hundreds of thousands of times and delivered malware designed to steal developer secrets.
- Disclosed
- Last updated
- Blast radius
- Hundreds of thousands of downloads across 19 science-focused PyPI packages
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- 19 science-focused PyPI packagesSpecific package names not provided in source text
A new Shai-Hulud supply-chain attack has compromised 19 packages on the Python Package Index (PyPI). The affected packages are science-focused and have been downloaded hundreds of thousands of times collectively.
The trojanized packages delivered malware designed to steal developer secrets from affected systems. The attack represents a significant supply-chain compromise targeting the Python ecosystem.
The specific package names were not detailed in the available source material, limiting the ability to provide a complete list of affected software.
Remediation
- Identify and audit all installations of the 19 compromised science-focused PyPI packages
- Review and rotate any developer secrets, credentials, or API keys that may have been exposed
- Monitor systems for signs of malware activity or unauthorized access
- Update to patched versions of affected packages once available
- Implement package verification and integrity checks in dependency management workflows
Sources
- New Shai-Hulud attack trojanizes 19 science-focused PyPI packages · BleepingComputer
Cite this entry
"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 8, 2026; last updated June 8, 2026. https://supplychainattack.org/incident/new-shai-hulud-attack-trojanizes-19-science-focused-pypi-packages-1gf74g
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in vtranalytic (PyPI)
The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.
PyPICompromised packageMalicious maintainer - containedcritical
Malicious code in dev-helper-bg (PyPI)
The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.
2026 07 Make HelperPyPICompromised packageMalicious commit - containedcritical
Malicious code in karpatkit (PyPI)
The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in mrmustard (PyPI)
A malicious version of the mrmustard package was published to PyPI containing code that exfiltrates SSH keys, AWS credentials, Kubernetes config, environment variables, and system identifiers to a remote endpoint. The payload includes multiple persistence mechanisms that survive package uninstallation.
PyPICompromised package