PyPI Installs Now Steal CI Secrets

A Python install can now be the compromise point. These Shai-Hulud/Miasma infections do not wait for imports or Python execution, so package review and Python-only monitoring miss the moment secrets are taken from developer and CI environments. Socket says the latest wave hit 37 malicious PyPI wheels across 19 packages. The releases used a `*-setup.pth` hook to start Bun and run an obfuscated JavaScript stealer, targeting developer, cloud, package-publishing, and CI/CD secrets. PyPI had already quarantined some affected releases and Socket reported the rest to the security team. That makes the install path itself the attack surface. Any workstation or runner that trusts third-party PyPI installs can leak credentials before the package ever appears in application code.

Part of the PlainSec briefing for 2026-06-08

Sources