Product
Bun
- First Reported
- Jul 21, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (5)
- Both of these attacks had a more sophisticated version of Shai-Hulud. The second wave leveraged bun to execute the file with the malicious code. The worm traveled far and infected many systems. TeamPCP, which will be Retrospective: How Malicious Software Updates Poison Development Environments
- case "bun": Datadog Details OpenCode Remote Code Execution Vulnerability and Exploit
- 0.0.0-365d4eb738d3146583431948d3ba6e27a32556be uses a preinstall script that fetches and runs the Bun installer, then executes is_it_this_simple.js with WORKFLOW_ID=release.yml, Mini Shai-Hulud Supply-Chain Attack Compromises 10 npm Package Versions
- other maintainers, were published with a malicious preinstall hook (setup.mjs) that downloads a standalone Bun runtime, executes an obfuscated second stage, harvests cloud and CI credentials, and republishes trojanized Active npm Supply-Chain Attack Compromises Keyv and Cacheable Packages
- Orphaned packages referenced by other, non-orphaned packages would then force npm or bun to fetch the malicious atomic-lockfile package. Atomic Arch Campaign Used Compromised AUR Packages to Deliver an Infostealer
Malware (10)
People (4)
Threat Actors (3)
MITRE ATT&CK (25)
Vendors (9)
Products (26)
Tools (3)
Industries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.