Shai-Hulud copycat campaign targets Python developers through PyPI typosquatting

· · June 9, 2026, 3:56 p.m.
Summary
A coordinated supply chain attack targeting Python packages on PyPI has been identified, which involves typosquatting of popular libraries like Flask and Requests. The attack introduced malicious packages that execute harmful code when installed without user awareness. The malware, reminiscent of a previous npm variant, steals credentials and propagates itself throughout CI/CD environments. GitLab's Vulnerability Research team shares details on the attack's execution, the behavior of the malicious packages, and remediation steps for affected developers.
AUTHOR
Sponsored
Zulip logo Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →