Package Installs Now Trigger Cross-Ecosystem Theft

The break is no longer just poisoned packages. Attackers are using ecosystem-specific startup hooks so a normal install can execute code immediately, steal secrets, and spread to the next package in line across both PyPI and NPM. Socket and other researchers tie the new Hades PyPI wave and the expanding NPM Miasma variants to the same Mini Shai-Hulud lineage. The PyPI branch uses `*-setup.pth` to run at Python startup, and the NPM side has added weaponized `binding.gyp` paths, with the published worm source helping the campaign splinter into faster, ecosystem-specific clones. That changes the trust boundary for package ecosystems. A poisoned install can now become a credential event on developer laptops and CI runners, and then a publishing foothold for more packages the victim can reach.

Part of the PlainSec briefing for 2026-06-08

Every edition of this story: Package Installs Now Trigger Cross-Ecosystem Theft

Sources