logo

Massive PyPI Supply Chain Attack Staged via Malware Startup Hooks

ID: f71e2b2a-0c7b-5225-81d4-f1e2b9e3c3e9

STIX ID: report--f71e2b2a-0c7b-5225-81d4-f1e2b9e3c3e9

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-07

Date Updated: 2026-06-07

Author: Do Son

...
...

## Executive Summary A coordinated supply-chain attack compromised hundreds of open-source packages (noted as ~448 artifacts across PyPI and npm), shipping malicious .pth startup hooks that bootstrap a Bun JavaScript runtime to run an obfuscated payload which harvests cloud credentials, SSH keys, and package tokens, then exfiltrates stolen data via automated GitHub repositories; the campaign is tracked as the Hades cluster within the Shai-Hulud/Miasma family. Immediate remediation recommended: remove infected packages, rotate exposed developer and cloud credentials, and inspect CI/CD pipelines for startup-hook execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.