Vulnerabilità ed exploit · Supply chain
Le installazioni dei pacchetti ora attivano il furto cross-ecosystem La compromissione non riguarda più solo i pacchetti avvelenati. Gli aggressori stanno usando hook di avvio specifici dell’ecosistema, così una normale installazione può eseguire codice immediatamente, rubare secret e diffondersi al pacchetto successivo in coda sia su PyPI sia su NPM.
5 fonti · 9 giu
Cronologia Fonti 9 giu SecurityWeek
Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks
The most recent variants of the self-propagating attacks are named Miasma and Hades.
originale 9 giu The Hacker News
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
Hades, a new PyPI branch of the Mini Shai-Hulud/Miasma supply chain campaign, hit 37 malicious wheels across 19 packages.
originale 8 giu BleepingComputer
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal developer secrets.
originale Part of the PlainSec briefing for 2026-06-08
Every edition of this story: Le installazioni dei pacchetti ora attivano il furto cross-ecosystem
Altro da oggi
Vulnerabilità ed exploit · Supply chain
Le installazioni dei pacchetti ora attivano il furto cross-ecosystem La compromissione non riguarda più solo i pacchetti avvelenati. Gli aggressori stanno usando hook di avvio specifici dell’ecosistema, così una normale installazione può eseguire codice immediatamente, rubare secret e diffondersi al pacchetto successivo in coda sia su PyPI sia su NPM.
5 fonti · 9 giu
Cronologia Fonti 9 giu SecurityWeek
Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks
The most recent variants of the self-propagating attacks are named Miasma and Hades.
originale 9 giu The Hacker News
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
Hades, a new PyPI branch of the Mini Shai-Hulud/Miasma supply chain campaign, hit 37 malicious wheels across 19 packages.
originale 8 giu BleepingComputer
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal developer secrets.
originale Part of the PlainSec briefing for 2026-06-08
Every edition of this story: Le installazioni dei pacchetti ora attivano il furto cross-ecosystem
Altro da oggi