logo

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

ID: 38bec67d-c602-52f4-bf92-bd8237fbf039

STIX ID: report--38bec67d-c602-52f4-bf92-bd8237fbf039

Feed Name: The Hacker News

Threat Score
82/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: [email protected] (The Hacker News)

...
...

A supply-chain campaign called Hades (linked to the Shai-Hulud/Miasma lineage) injected malicious code into multiple PyPI packages and wheel artifacts so that Python startup or package import executes a dropper. The dropper fetches the Bun JavaScript runtime and runs an obfuscated stealer that harvests a broad set of developer and CI/CD secrets (GitHub, npm, PyPI, cloud credentials, SSH keys, config files), exfiltrates via GitHub repositories, includes LLM prompt-injection and locale-based evasion, and implements propagation and destructive behaviors (e.g., wiper service).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.