'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud
ID: 1cc07045-c1bb-5e47-9951-7ecb03fda10c
STIX ID: report--1cc07045-c1bb-5e47-9951-7ecb03fda10c
Feed Name: CosmicBytez Labs
Threat Score
Researchers uncovered the 'Hades' supply-chain campaign that compromised 37 Python wheel distributions across 19 packages to exfiltrate developer credentials and self-propagate using stolen maintainer accounts; the campaign leverages obfuscation, delayed payload activation, and encrypted C2, and organizations are advised to pin dependencies, enable package integrity verification, and audit installs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
