掃碼下載
BTC $63,762.12 +1.08%
ETH $1,673.02 +0.67%
BNB $602.65 +0.38%
XRP $1.12 +0.47%
SOL $67.29 +1.47%
TRX $0.3153 +0.65%
DOGE $0.0869 +1.21%
ADA $0.1729 +2.43%
BCH $207.26 +2.33%
LINK $7.95 +1.85%
HYPE $58.63 +1.92%
AAVE $66.16 +3.99%
SUI $0.7617 +1.45%
XLM $0.1902 +0.15%
ZEC $414.37 -1.78%
BTC $63,762.12 +1.08%
ETH $1,673.02 +0.67%
BNB $602.65 +0.38%
XRP $1.12 +0.47%
SOL $67.29 +1.47%
TRX $0.3153 +0.65%
DOGE $0.0869 +1.21%
ADA $0.1729 +2.43%
BCH $207.26 +2.33%
LINK $7.95 +1.85%
HYPE $58.63 +1.92%
AAVE $66.16 +3.99%
SUI $0.7617 +1.45%
XLM $0.1902 +0.15%
ZEC $414.37 -1.78%

Shai-Hulud Hades 新變種攻擊 PyPI,利用 Python 到 Bun 跨運行時鏈竊取憑證

2026-06-12 20:57:59
收藏

ChainCatcher 消息,据慢雾披露,发现 Shai-Hulud Hades 新變種正在攻擊 PyPI。惡意包會投放 .pth 檔案,在 Python 啟動時自動執行,並檢測本地是否安裝 Bun;若未安裝,則從 GitHub Releases 下載官方 Bun 二進制檔案,再執行多層混淆 JavaScript 載荷,用於竊取 GitHub、npm、AWS 及雲服務憑證。

慢雾稱,該變種與此前 Shai-Hulud 攻擊使用相同 RSA 公鑰和基礎設施,並具備加密外傳、持久化、CI/CD 注入及 GitHub Actions 注入等能力。

app_icon
ChainCatcher 與創新者共建Web3世界