Vulnerabilità · 112 giorni fa
La compromissione non riguarda più solo i pacchetti avvelenati. Gli aggressori stanno usando hook di avvio specifici dell’ecosistema, così una normale installazione può eseguire codice immediatamente, rubare secret e diffondersi al pacchetto successivo in coda sia su PyPI sia su NPM.
5 fonti che coprono questa storia
Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks
The most recent variants of the self-propagating attacks are named Miasma and Hades.
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
Hades, a new PyPI branch of the Mini Shai-Hulud/Miasma supply chain campaign, hit 37 malicious wheels across 19 packages.
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal developer secrets.
'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud
The latest attacks, which hit 37 PyPI wheels and 19 code packages, show a continued evolution of the supply chain threat.
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads w...
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
Part of the PlainSec briefing for 2026-06-08