MEDIUMSupply Chain
Global

New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

·Source: BleepingComputer

Updated:

Executive Summary

Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal developer secrets. [...]

Analysis

Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal developer secrets. [...]
Source Attribution

Originally published by BleepingComputer on Jun 8, 2026.

Related Threats