扫码下载
BTC $63,901.93 +2.02%
ETH $1,688.78 +3.27%
BNB $609.54 +1.91%
XRP $1.13 +3.31%
SOL $67.95 +4.35%
TRX $0.3135 -2.28%
DOGE $0.0902 +6.50%
ADA $0.1727 +4.63%
BCH $206.72 +3.89%
LINK $7.96 +2.96%
HYPE $60.36 +6.88%
AAVE $65.13 +3.56%
SUI $0.7629 +2.22%
XLM $0.1927 +3.53%
ZEC $428.90 +2.26%
BTC $63,901.93 +2.02%
ETH $1,688.78 +3.27%
BNB $609.54 +1.91%
XRP $1.13 +3.31%
SOL $67.95 +4.35%
TRX $0.3135 -2.28%
DOGE $0.0902 +6.50%
ADA $0.1727 +4.63%
BCH $206.72 +3.89%
LINK $7.96 +2.96%
HYPE $60.36 +6.88%
AAVE $65.13 +3.56%
SUI $0.7629 +2.22%
XLM $0.1927 +3.53%
ZEC $428.90 +2.26%

Shai-Hulud Hades 新变种攻击 PyPI,利用 Python 到 Bun 跨运行时链窃取凭证

2026-06-12 20:57:59
收藏

ChainCatcher 消息,据慢雾披露,发现 Shai-Hulud Hades 新变种正在攻击 PyPI。恶意包会投放 .pth 文件,在 Python 启动时自动执行,并检测本地是否安装 Bun;若未安装,则从 GitHub Releases 下载官方 Bun 二进制文件,再执行多层混淆 JavaScript 载荷,用于窃取 GitHub、npm、AWS 及云服务凭证。

慢雾称,该变种与此前 Shai-Hulud 攻击使用相同 RSA 公钥和基础设施,并具备加密外传、持久化、CI/CD 注入及 GitHub Actions 注入等能力。

app_icon
ChainCatcher 与创新者共建Web3世界