logo

Shai-Hulud: Miasma, Hades, & AI Scanner Evasion

ID: aa69973e-d837-5a96-932b-61f91b7379b4

STIX ID: report--aa69973e-d837-5a96-932b-61f91b7379b4

Feed Name: Zscaler Security Research Blog

Threat Score
82/100

Date Published: 2026-06-12

Date Updated: 2026-07-04

...
...

Hades PyPI supply-chain malware (detected June 8, 2026) compromised 37 wheels across 19 packages using .pth persistence, layered obfuscation, strong encryption, and obfuscator-wrapped JavaScript; notably the campaign embedded an adversarial prompt-injection in _index.js to bypass LLM-based automated scanners, and its C2 evolved through GitHub dead drops, ICP blockchain canisters, and Session Protocol to increase takedown resistance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.