Shai-Hulud: Miasma, Hades, & AI Scanner Evasion
ID: aa69973e-d837-5a96-932b-61f91b7379b4
STIX ID: report--aa69973e-d837-5a96-932b-61f91b7379b4
Feed Name: Zscaler Security Research Blog
Threat Score
Hades PyPI supply-chain malware (detected June 8, 2026) compromised 37 wheels across 19 packages using .pth persistence, layered obfuscation, strong encryption, and obfuscator-wrapped JavaScript; notably the campaign embedded an adversarial prompt-injection in _index.js to bypass LLM-based automated scanners, and its C2 evolved through GitHub dead drops, ICP blockchain canisters, and Session Protocol to increase takedown resistance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
