Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Shai-Hulud Supply Chain Attacks Target NPM and PyPI Packages

Shai-Hulud Supply Chain Attacks Target NPM and PyPI Packages

Posted on June 9, 2026 By CWS

Recent Shai-Hulud supply chain attacks have affected more than 100 packages within the NPM and PyPI ecosystems, as reported by cybersecurity experts. These attacks, active since September 2025, have targeted open source software communities with increasing frequency, particularly after the Trivy vulnerability scanner incident.

Surge in Attacks Since May

In May, the hacking group TeamPCP released the source code for Shai-Hulud, leading to the emergence of new clones. By June 1, updated variants were used in expansive, organized attacks, starting with the Red Hat incident, which compromised 32 packages in the Hybrid Cloud Console JavaScript ecosystem.

The attacks have evolved, introducing the ‘Miasma’ variant, which was highlighted by the inclusion of the phrase “Miasma: The Spreading Blight” in the payload. Security firm Ox Security found several malicious NPM packages containing a weaponized binding.gyp file designed to circumvent standard execution procedures.

Miasma Variant Characteristics

Miasma, a descendant of the Mini Shai-Hulud, operates as a multi-stage dropper initiated during NPM package installation. According to Harness, it scans systems and cloud services for sensitive information like credentials and API keys, using this data to further propagate the attack.

By June 5, entities such as Snyk, Sonatype, and StepSecurity identified 57 affected NPM packages and over 300 malicious package versions linked to Miasma. The attacks have impacted several ecosystems including Vapi server SDK and ai-sdk-ollama.

Emergence of the Hades Variant

Following the Miasma attacks, researchers detected another Shai-Hulud variant named ‘Hades’ in roughly two dozen PyPI packages. This variant, marked by the string “Hades – The End for the Damned,” was discovered in an initial set of 19 packages, employing a *-setup.pth file to execute code upon Python startup.

Socket reports that Hades is essentially the PyPI branch of Miasma, exhibiting similar credential-harvesting and spreading tactics. On June 8, a second wave targeted more PyPI packages, with phantom releases appearing on PyPI without corresponding GitHub versions, affecting at least 29 packages according to StepSecurity.

The attacks have involved a total of 471 malicious artifacts across NPM and PyPI, including numerous harmful PyPI wheel artifacts related to the Hades Mini Shai-Hulud worm.

As these attacks continue to evolve, the cybersecurity community remains vigilant in addressing the vulnerabilities in open source supply chains. The incidents underscore the necessity for enhanced security measures to protect against such sophisticated threats.

Security Week News Tags:Cybersecurity, Hades, Malware, Miasma, NPM, open source security, OSS, PyPI, Shai-Hulud, supply chain attacks, TeamPCP

Post navigation

Previous Post: Unveiling the Hidden Risks in Network Security Operations
Next Post: Phishing Scams Exploit AI Tool Brands for Credential Theft

Related Posts

Robo-Advisor Betterment Discloses Data Breach Robo-Advisor Betterment Discloses Data Breach Security Week News
North Korean APT37’s New Tools Target Air-Gapped Systems North Korean APT37’s New Tools Target Air-Gapped Systems Security Week News
Trent AI Launches with M Seed Funding Boost Trent AI Launches with $13M Seed Funding Boost Security Week News
Cisco Says User Data Stolen in CRM Hack Cisco Says User Data Stolen in CRM Hack Security Week News
‘PackageGate’ Flaws Open JavaScript Ecosystem to Supply Chain Attacks ‘PackageGate’ Flaws Open JavaScript Ecosystem to Supply Chain Attacks Security Week News
Asymmetric Security Emerges From Stealth With .2 Million in Funding Asymmetric Security Emerges From Stealth With $4.2 Million in Funding Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cryptographic Invisibility Revolutionizes AI App Security
  • AI-Driven Worm Revolutionizes Cybersecurity Threats
  • Weedhack Malware Poses Threat to Minecraft Users
  • SAP Addresses Major Vulnerabilities in NetWeaver and Commerce
  • Cyber Attacks Exploit WinRAR Flaw Against Ukraine

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cryptographic Invisibility Revolutionizes AI App Security
  • AI-Driven Worm Revolutionizes Cybersecurity Threats
  • Weedhack Malware Poses Threat to Minecraft Users
  • SAP Addresses Major Vulnerabilities in NetWeaver and Commerce
  • Cyber Attacks Exploit WinRAR Flaw Against Ukraine

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark