Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Popular lightning PyPI Package Backdoored in Latest Shai-Hulud Wave

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Henrik Plate
Word Count
2,618
Company Posts That Month
35
Language
English
Hacker News Points
-
Post removed?
No
Summary

Two versions of the popular Python package "lightning" (2.6.2 and 2.6.3) were identified as malicious and removed after being downloaded approximately 8 million times per month. These compromised versions initiated a hidden background process upon importing lightning, downloading and executing an obfuscated JavaScript payload via an external source, using the Bun JavaScript runtime. This behavior aligns with tactics seen in recent Shai-Hulud campaigns, utilizing credential theft, self-propagation, and persistence techniques. Organizations using the affected versions are advised to treat their environments as compromised, revert to known-safe releases, rotate credentials, and audit for unusual outbound connections. The malicious payload was designed to infect both Python and JavaScript ecosystems, employing strategies such as npm package poisoning and GitHub repository tampering for replication. The campaign emphasized credential collection from various sources, including AWS, Azure, GCP, and GitHub, with potential for long-term intrusions due to the sensitive environments affected, such as cloud-attached notebooks and automated release pipelines. The incident highlights the importance of a version cooldown period to mitigate the impact of supply chain attacks, allowing time for detection and removal before widespread adoption.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 10 1,821 338 111 +22%
AI Coding Assistant 1 1,480 382 153 +18%
Real-time 1 6,296 1,346 246 -2%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.