Popular lightning PyPI Package Backdoored in Latest Shai-Hulud Wave
Blog post from Endor Labs
Two versions of the popular Python package "lightning" (2.6.2 and 2.6.3) were identified as malicious and removed after being downloaded approximately 8 million times per month. These compromised versions initiated a hidden background process upon importing lightning, downloading and executing an obfuscated JavaScript payload via an external source, using the Bun JavaScript runtime. This behavior aligns with tactics seen in recent Shai-Hulud campaigns, utilizing credential theft, self-propagation, and persistence techniques. Organizations using the affected versions are advised to treat their environments as compromised, revert to known-safe releases, rotate credentials, and audit for unusual outbound connections. The malicious payload was designed to infect both Python and JavaScript ecosystems, employing strategies such as npm package poisoning and GitHub repository tampering for replication. The campaign emphasized credential collection from various sources, including AWS, Azure, GCP, and GitHub, with potential for long-term intrusions due to the sensitive environments affected, such as cloud-attached notebooks and automated release pipelines. The incident highlights the importance of a version cooldown period to mitigate the impact of supply chain attacks, allowing time for detection and removal before widespread adoption.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 10 | 1,821 | 338 | 111 | +22% |
| AI Coding Assistant | 1 | 1,480 | 382 | 153 | +18% |
| Real-time | 1 | 6,296 | 1,346 | 246 | -2% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.