Shai-Hulud Supply-Chain Attack Trojanizes 19 PyPI Packages
A second-wave Shai-Hulud supply-chain attack trojanized 19 science-focused Python packages on the PyPI repository, delivering credential-stealing malware. Corroborating reports link a related Rust-based infostealer dubbed IronWorm to 30–36 npm packages, self-propagating via trusted publishing workflows and exfiltrating cloud, AI, and developer credentials. The combined PyPI/npm exposure creates potential aggregation risk across cyber portfolios, though no confirmed insured losses or breach notifications have been reported.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. Loss pathway: Supply-chain compromise across PyPI and npm ecosystems creates aggregation risk for cyber, tech E&O, and crime/fidelity books where insured developers or organizations may have pulled trojanized packages. Hundreds of thousands of collective PyPI downloads and a 30–36 package npm footprint broaden the potential accumulation surface. Limit: No confirmed insured losses, breach notifications, or specific affected entities reported; impact scale remains uncertain pending disclosure of downstream compromise and credential misuse.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialLloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts