Massive PyPI Supply Chain Attack Staged via Malware Startup Hooks
ID: f71e2b2a-0c7b-5225-81d4-f1e2b9e3c3e9
STIX ID: report--f71e2b2a-0c7b-5225-81d4-f1e2b9e3c3e9
Feed Name: securityonline.info
## Executive Summary A coordinated supply-chain attack compromised hundreds of open-source packages (noted as ~448 artifacts across PyPI and npm), shipping malicious .pth startup hooks that bootstrap a Bun JavaScript runtime to run an obfuscated payload which harvests cloud credentials, SSH keys, and package tokens, then exfiltrates stolen data via automated GitHub repositories; the campaign is tracked as the Hades cluster within the Shai-Hulud/Miasma family. Immediate remediation recommended: remove infected packages, rotate exposed developer and cloud credentials, and inspect CI/CD pipelines for startup-hook execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
