logo

Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave

ID: 3757c617-993a-5d05-9930-d1023d7ae91e

STIX ID: report--3757c617-993a-5d05-9930-d1023d7ae91e

Feed Name: Socket Blog

Threat Score
85/100

Date Published: 2026-06-07

Date Updated: 2026-06-11

Author: Socket Research Team

...
...

Socket discovered a coordinated PyPI supply-chain compromise (37 malicious wheels across 19 packages) that installs executable .pth startup hooks to download/install the Bun runtime and run an obfuscated JavaScript payload (Hades, a branch of the Shai-Hulud/Miasma lineage) designed to steal developer, CI/CD, and cloud credentials and exfiltrate data (notably via GitHub repositories, artifacts, and camouflage to an Anthropic API host); the report includes IOCs, hashes, detection rules, and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.