Shai-Hulud copycat campaign targets Python developers through PyPI typosquatting
…Layer Key IV Bun downloader c95506221d18936328fbc7ddcd21e3dd 48da5faeafac0ac88a410bb0 Worm payload 7557c4e782a0622159476d1ea10d5236 55a7d25e0e61b77cc175bcc3 Credential harvesting Once running, the worm goes after credentials across every major cloud and CI/CD platform: GitHub Actions : GITHUB_TOKEN…