{"id":815,"date":"2026-08-19T08:38:33","date_gmt":"2026-08-19T03:08:33","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=815"},"modified":"2026-08-19T08:48:48","modified_gmt":"2026-08-19T03:18:48","slug":"shai-hulud-pypi-science-packages-credential-theft","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/","title":{"rendered":"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages"},"content":{"rendered":"<p>A newly identified Shai-Hulud software supply-chain campaign has compromised multiple scientific and bioinformatics packages hosted on PyPI, exposing a risk that extends far beyond individual developer workstations. By abusing Python&#8217;s startup mechanisms, the malware can execute automatically in environments where affected packages are installed, including development systems, notebook environments, and CI\/CD pipelines.<\/p>\n<p>The campaign highlights a persistent challenge in modern software development: trusted open-source dependencies often have access to the same repositories, cloud environments, and secrets that organizations rely on to build and deliver applications. When a compromised package gains execution within these environments, it can become an entry point for credential theft, repository compromise, cloud account abuse, and downstream supply-chain attacks.<\/p>\n<p>For organizations that support research workloads, developer platforms, or Python-based automation, the incident serves as another reminder that dependency security is now a core component of enterprise security strategy, not merely a software development concern.<\/p>\n<h2>How the Shai-Hulud Supply-Chain Attack Works<\/h2>\n<p>The campaign leverages Python&#8217;s .pth startup hook mechanism, a legitimate feature that allows code to execute automatically when the Python interpreter initializes. Once a compromised package is installed, the malicious .pth file can trigger during routine Python activity, including interactive sessions, notebook launches, package-management operations, automated testing, and CI\/CD workflows.<\/p>\n<p>After execution, the malware attempts to download the Bun JavaScript runtime from GitHub and use it to run an obfuscated JavaScript payload named <code>_index.js<\/code>. This approach allows attackers to move much of the malicious logic outside the Python package itself, making analysis and detection more difficult while enabling rapid updates to payload behavior.<\/p>\n<p>The payload is designed to harvest a broad range of credentials and sensitive artifacts commonly found on developer endpoints and build infrastructure, including:<\/p>\n<ul>\n<li>Source code repository credentials and access tokens<\/li>\n<li>CI\/CD secrets and automation workflow data<\/li>\n<li>Cloud provider credentials across AWS, Google Cloud, and Microsoft Azure environments<\/li>\n<li>Package registry tokens used for software publishing<\/li>\n<li>SSH keys, environment files, and shell history data<\/li>\n<li>Container, Kubernetes, and secrets-management artifacts<\/li>\n<li>AI development tooling configurations, including Claude and MCP-related settings<\/li>\n<\/ul>\n<p>The malware also incorporates persistence techniques intended to survive beyond the initial execution. Reported mechanisms include:<\/p>\n<ul>\n<li>Creation of systemd services on Linux systems<\/li>\n<li>Deployment of LaunchAgents on macOS devices<\/li>\n<li>Modification of GitHub Actions workflow files<\/li>\n<li>Alteration of Claude and MCP configuration files to maintain access and enable continued execution<\/li>\n<\/ul>\n<p>From a defender&#8217;s perspective, the most significant aspect of the attack is not the malware&#8217;s complexity but its positioning. By executing inside trusted development and automation environments, the malicious package can access the same credentials, repositories, and infrastructure resources that organizations depend on to build and deploy software. This significantly increases the potential impact of a single compromised dependency.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement.webp?format=webp\" class=\"resource-box__image\" alt=\"Hexnode_UEM-Capability-statement\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement.webp?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement-300x225.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement-768x576.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Hexnode_UEM-Capability-statement\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode UEM Capability Statement\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Download the capability statement to get a quick glimpse into Hexnode's capabilities and features.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/brochures\/hexnode-uem-capability-statement\/'>\n                            Get the capability statement\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>How Hexnode Can Help Reduce Exposure<\/h2>\n<p>A compromise like Shai-Hulud is difficult to detect through preventive controls alone because the malicious code executes inside trusted developer and automation environments. Organizations need visibility into suspicious behavior after package installation, as well as the ability to quickly investigate and contain affected endpoints.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> can help security teams identify and investigate indicators associated with this type of attack, including:<\/p>\n<ul>\n<li>Unusual Python process activity originating from development or research environments<\/li>\n<li>Unexpected execution of secondary runtimes or tools, such as Bun<\/li>\n<li>Suspicious credential-access behavior targeting local files, tokens, or configuration stores<\/li>\n<li>Attempts to establish persistence on managed endpoints<\/li>\n<li>Abnormal outbound connections and potential data exfiltration activity<\/li>\n<li>Process, file, and network events that may indicate post-compromise activity<\/li>\n<\/ul>\n<p>By correlating endpoint telemetry across managed devices, security teams can gain greater visibility into potentially malicious behavior and accelerate incident investigation and response workflows.<\/p>\n<p>On the device management side, <a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a> can help strengthen the security posture of developer and research workstations through centralized endpoint governance. Key controls include:<\/p>\n<ul>\n<li>Enforcing device compliance and security policies<\/li>\n<li>Maintaining patch and update compliance across supported endpoints<\/li>\n<li>Applying and monitoring full-disk encryption policies<\/li>\n<li>Managing approved applications and endpoint configurations<\/li>\n<li>Performing remote actions and remediation tasks from a centralized console<\/li>\n<li>Supporting endpoint management across Windows, macOS, and Linux environments<\/li>\n<\/ul>\n<p>These capabilities help reduce the attack surface of developer systems and improve an organization&#8217;s ability to respond quickly when a software supply-chain incident affects managed endpoints.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UEM-Incident-Management-From-Monitoring-to-Remediation-with-the-New-Incidents-Tab-1024x576-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>UEM Incident Management: From Monitoring to Remediation with the New Incidents Tab<\/h4><p>Hexnode\u2019s Incidents tab centralizes incident tracking, ownership, and remediation from a single console.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/uem-incident-management-monitoring-to-remediation\/\" aria-label=\"UEM Incident Management: From Monitoring to Remediation with the New Incidents Tab\"><\/a><\/div><\/div><\/div><\/p>\n<h2>Conclusion<\/h2>\n<p>The Shai-Hulud campaign underscores how software supply-chain risk extends beyond traditional enterprise applications. Open-source packages used in research, development, data science, and automation workflows often operate in environments that contain highly privileged credentials, making them attractive targets for attackers.<\/p>\n<p>The incident also demonstrates how a single compromised dependency can create opportunities for credential theft, repository compromise, cloud environment exposure, and downstream operational risk. As organizations continue to rely on open-source ecosystems, securing the software supply chain must remain a shared responsibility across security, platform engineering, and development teams.<\/p>\n<p>To reduce exposure, organizations should prioritize:<\/p>\n<ul>\n<li>Dependency governance and package-source monitoring<\/li>\n<li>Continuous endpoint visibility and threat detection<\/li>\n<li>Rapid credential and secret rotation following suspected compromise<\/li>\n<li>Hardened developer and research workstations<\/li>\n<li>Strong controls around CI\/CD pipelines and cloud access credentials<\/li>\n<\/ul>\n<p>For security leaders, the lesson is clear: protecting enterprise assets now requires the same level of scrutiny for third-party dependencies as it does for endpoints, identities, and cloud infrastructure.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f <\/h5><p>Strengthen your defenses against supply-chain threats with unified endpoint security, visibility, and response from Hexnode.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A newly identified Shai-Hulud software supply-chain campaign has compromised multiple scientific and bioinformatics packages hosted&#8230;<\/p>\n","protected":false},"author":8,"featured_media":820,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,15],"class_list":["post-815","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-malware","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>New Shai-Hulud attack trojanizes 19 science-focused PyPI packages<\/title>\n<meta name=\"description\" content=\"Shai-Hulud PyPI attack trojanized 19 science-focused PyPI packages to steal developer, cloud, GitHub, Vault and CI\/CD secrets.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages\" \/>\n<meta property=\"og:description\" content=\"Shai-Hulud PyPI attack trojanized 19 science-focused PyPI packages to steal developer, cloud, GitHub, Vault and CI\/CD secrets.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-19T03:08:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T03:18:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Shai-Hulud-PyPI-attack-1024x531-1-1.webp?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"531\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages\",\"datePublished\":\"2026-08-19T03:08:33+00:00\",\"dateModified\":\"2026-08-19T03:18:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/\"},\"wordCount\":859,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Shai-Hulud-PyPI-attack-1024x531-1-1.webp?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/\",\"name\":\"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Shai-Hulud-PyPI-attack-1024x531-1-1.webp?format=webp\",\"datePublished\":\"2026-08-19T03:08:33+00:00\",\"dateModified\":\"2026-08-19T03:18:48+00:00\",\"description\":\"Shai-Hulud PyPI attack trojanized 19 science-focused PyPI packages to steal developer, cloud, GitHub, Vault and CI\\\/CD secrets.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Shai-Hulud-PyPI-attack-1024x531-1-1.webp?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Shai-Hulud-PyPI-attack-1024x531-1-1.webp?format=webp\",\"width\":1024,\"height\":531,\"caption\":\"Shai-Hulud-PyPI-attack\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/shai-hulud-pypi-science-packages-credential-theft\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages","description":"Shai-Hulud PyPI attack trojanized 19 science-focused PyPI packages to steal developer, cloud, GitHub, Vault and CI\/CD secrets.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/","og_locale":"en_US","og_type":"article","og_title":"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages","og_description":"Shai-Hulud PyPI attack trojanized 19 science-focused PyPI packages to steal developer, cloud, GitHub, Vault and CI\/CD secrets.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-19T03:08:33+00:00","article_modified_time":"2026-08-19T03:18:48+00:00","og_image":[{"width":1024,"height":531,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Shai-Hulud-PyPI-attack-1024x531-1-1.webp?format=webp","type":"image\/webp"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages","datePublished":"2026-08-19T03:08:33+00:00","dateModified":"2026-08-19T03:18:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/"},"wordCount":859,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Shai-Hulud-PyPI-attack-1024x531-1-1.webp?format=webp","articleSection":["Identity Abuse","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/","url":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/","name":"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Shai-Hulud-PyPI-attack-1024x531-1-1.webp?format=webp","datePublished":"2026-08-19T03:08:33+00:00","dateModified":"2026-08-19T03:18:48+00:00","description":"Shai-Hulud PyPI attack trojanized 19 science-focused PyPI packages to steal developer, cloud, GitHub, Vault and CI\/CD secrets.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Shai-Hulud-PyPI-attack-1024x531-1-1.webp?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Shai-Hulud-PyPI-attack-1024x531-1-1.webp?format=webp","width":1024,"height":531,"caption":"Shai-Hulud-PyPI-attack"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/shai-hulud-pypi-science-packages-credential-theft\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/815","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=815"}],"version-history":[{"count":4,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/815\/revisions"}],"predecessor-version":[{"id":819,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/815\/revisions\/819"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/820"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=815"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=815"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}