扫码下载
BTC $63,730.64 +0.07%
ETH $1,672.02 -0.32%
BNB $603.96 -0.36%
XRP $1.12 -0.12%
SOL $67.36 +0.41%
TRX $0.3163 +1.32%
DOGE $0.0872 +0.58%
ADA $0.1724 +0.43%
BCH $207.42 +1.28%
LINK $7.95 +0.64%
HYPE $58.19 -1.61%
AAVE $66.59 +2.44%
SUI $0.7664 +1.26%
XLM $0.1902 -1.77%
ZEC $413.26 -6.21%
BTC $63,730.64 +0.07%
ETH $1,672.02 -0.32%
BNB $603.96 -0.36%
XRP $1.12 -0.12%
SOL $67.36 +0.41%
TRX $0.3163 +1.32%
DOGE $0.0872 +0.58%
ADA $0.1724 +0.43%
BCH $207.42 +1.28%
LINK $7.95 +0.64%
HYPE $58.19 -1.61%
AAVE $66.59 +2.44%
SUI $0.7664 +1.26%
XLM $0.1902 -1.77%
ZEC $413.26 -6.21%

Shai-Hulud Hades 新变种攻击 PyPI,利用 Python 到 Bun 跨运行时链窃取凭证

2026-06-12 20:57:59
收藏

ChainCatcher 消息,据慢雾披露,发现 Shai-Hulud Hades 新变种正在攻击 PyPI。恶意包会投放 .pth 文件,在 Python 启动时自动执行,并检测本地是否安装 Bun;若未安装,则从 GitHub Releases 下载官方 Bun 二进制文件,再执行多层混淆 JavaScript 载荷,用于窃取 GitHub、npm、AWS 及云服务凭证。

慢雾称,该变种与此前 Shai-Hulud 攻击使用相同 RSA 公钥和基础设施,并具备加密外传、持久化、CI/CD 注入及 GitHub Actions 注入等能力。

app_icon
ChainCatcher 与创新者共建Web3世界