Vulnerabilities · 97 days ago
The break is no longer just poisoned packages. Attackers are using ecosystem-specific startup hooks so a normal install can execute code immediately, steal secrets, and spread to the next package in line across both PyPI and NPM.
Socket and other researchers tie the new Hades PyPI wave and the expanding NPM Miasma variants to the same Mini Shai-Hulud lineage. The PyPI branch uses `*-setup.pth` to run at Python startup, and the NPM side has added weaponized `binding.gyp` paths, with the published worm source helping the campaign splinter into faster, ecosystem-specific clones.
That changes the trust boundary for package ecosystems. A poisoned install can now become a credential event on developer laptops and CI runners, and then a publishing foothold for more packages the victim can reach.
5 sources covering this story
Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks
The most recent variants of the self-propagating attacks are named Miasma and Hades.
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
Hades, a new PyPI branch of the Mini Shai-Hulud/Miasma supply chain campaign, hit 37 malicious wheels across 19 packages.
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal developer secrets.
'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud
The latest attacks, which hit 37 PyPI wheels and 19 code packages, show a continued evolution of the supply chain threat.
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads w...
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
Part of the PlainSec briefing for 2026-06-08