Tracked campaign · PyPI
Shai-Hulud (PyPI)
Self-propagating worm targeting PyPI packages. Uses .pth startup hooks and/or the Bun JS runtime to run obfuscated JavaScript credential-stealers on every Python invocation post-install.
852 packages attributedPyPI ecosystemosv source
Attribution basis
- shared malware fingerprint
- OSV advisory cluster
Sample attributed packages
obra@3.7.50ccsilo@0.6.5chimera-run@0.8.0claude-agent-sdk@0.2.101ciris-agent@2.9.6calfkit-tools@0.1.0clawdeck@0.5.3sumo-qa@0.46.0conduct-cli@0.4.95conduct-cli@0.4.94langchain-agentx-python@1.0.7yt-dlp@2026.6.12.235626.dev0plato-sdk-v2@2.98.0superdoc-sdk@1.16.1pmsec@0.14.0codeboarding@0.12.2praisonai@4.6.56nuguard@0.7.3skilltotal@0.7.4sumo-qa@0.45.0deepline@1.0.93pdd-cli@0.0.272mindroom@2026.6.140claude-jacked@0.46.5praisonai@4.6.55arifos@2026.6.12mindroom@2026.6.139deepagents-code@0.1.15claude-mpm@6.5.41ralph-workflow@0.8.12