Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
ID: 38bec67d-c602-52f4-bf92-bd8237fbf039
STIX ID: report--38bec67d-c602-52f4-bf92-bd8237fbf039
Feed Name: The Hacker News
A supply-chain campaign called Hades (linked to the Shai-Hulud/Miasma lineage) injected malicious code into multiple PyPI packages and wheel artifacts so that Python startup or package import executes a dropper. The dropper fetches the Bun JavaScript runtime and runs an obfuscated stealer that harvests a broad set of developer and CI/CD secrets (GitHub, npm, PyPI, cloud credentials, SSH keys, config files), exfiltrates via GitHub repositories, includes LLM prompt-injection and locale-based evasion, and implements propagation and destructive behaviors (e.g., wiper service).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
