PyPI Attackers Keep Reworking the Same Secret Stealer
The break is not a single bad PyPI package. The campaign is changing loader types and package themes so the same credential stealer keeps reaching developer laptops and CI jobs even when defenders look for one wheel shape or one payload layout. That means pattern-matching for a known filename, hook, or embedded JavaScript target will miss part of the wave.
Socket added 23 new PyPI package-version artifacts to the earlier 37 malicious wheels tied to Mini Shai-Hulud, Miasma, and Hades. The new wave spans bioinformatics packages, AI and MCP-themed packages, and typosquat-style names, with loaders that use .pth hooks, native .abi3.so extensions, or sys.path payload discovery to launch a Bun-based JavaScript stealer.
The target set is the secret store on developer systems: cloud credentials, registry tokens, SSH keys, Kubernetes material, and AI tool config. As the loaders change, the persistence risk stays the same — a compromised dependency can pull standing secrets out of build and dev environments without a browser phish or password prompt.