Skip to content
The Coolest Info

The Coolest Info

Subscribe
The Coolest Info

The Coolest Info

PyPI

  • Security

Shai-Hulud Strikes Again: 19 Science PyPI Packages Trojanized to Steal Developer Secrets

June 9, 2026June 9, 20260

The Shai-Hulud supply-chain campaign compromised 19 scientific PyPI packages (Dynamo, Spateo, CoolBox, U-FISH, and more) with malware that steals developer secrets — cloud keys, publishing tokens, SSH keys, and AI tool configs. The payload triggers on any Python invocation.

Recent Posts

  • OnePlus Is Chasing 240Hz Phone Screens — Here’s Why That’s Complicated
  • He Lost €5,900 to a Bank Spoofing Scam — Then Watched His Bank Blame Him and Lose in Court
  • Attackers Abuse Google DoubleClick to Stealthily Deliver .NET Malware
  • Microsoft Investigative Playbook for Copilot and Azure AI: A Practical Guide
  • AethexAI Raises $3M to Build Voice AI That Actually Works in Africa and the Middle East

Recent Comments

No comments to show.

Archives

  • June 2026

Categories

  • crypto
  • Security
  • Tech
    Online Newspaper - News / Magazine WordPress Theme 2026.
    Back To Top