logo

'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud

ID: 72c007b4-0cbe-54de-8547-22815289dd4e

STIX ID: report--72c007b4-0cbe-54de-8547-22815289dd4e

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-06-08

Date Updated: 2026-06-15

Author: Elizabeth Montalbano

...
...

Researchers from Socket detailed a Mini Shai-Hulud campaign that infected PyPI packages (37 wheels across 19 packages) to execute a Bun-based JavaScript credential stealer via Python .pth startup abuse; the worm self-propagates, steals developer/cloud/CI secrets during install, and uses Hades-themed exfiltration markers. PyPI quarantined affected releases; organizations are advised to audit environments, assume any install-time secrets may be compromised, and rotate credentials while implementing continuous monitoring of package installations and artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.