Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hades Attack Targets PyPI: 19 Packages Compromised

Hades Attack Targets PyPI: 19 Packages Compromised

Posted on June 9, 2026 By CWS

The recent emergence of the Hades attack signifies a new chapter in the ongoing saga of supply chain threats, specifically targeting the Python Package Index (PyPI). This campaign involves 37 malicious wheel artifacts spread across 19 different packages, reflecting a refinement of the earlier Mini Shai-Hulud-style operations. The key focus remains on exploiting specific ecosystems through compromised packages.

Understanding the Hades Attack Mechanism

The Hades attack involves the deployment of a malicious *-setup.pth file, which is designed to execute during Python startup. This file downloads the Bun JavaScript runtime and initiates an obfuscated JavaScript payload. Unlike previous campaigns, this payload does not require the victim to import the compromised package, making it particularly insidious.

Once activated, the payload can harvest a broad spectrum of sensitive information, including credentials from platforms such as GitHub, npm, and AWS. These credentials are then utilized to facilitate further exploitation and propagation of the malware.

Noteworthy Changes and Techniques

A significant shift in the Hades campaign is the use of the *-setup.pth file, enabling the payload to execute without user intervention. Previously, harvested data was exported to public GitHub repositories under the name ‘Miasma: The Spreading Blight.’ However, the current campaign utilizes descriptors like ‘Hades – The End for the Damned,’ marking a new phase in its evolution.

The attack also includes a novel approach to misleading AI security scanners. By embedding an entry point in the package’s “__init__.py” file, the malware employs a plain-text prompt injection to deceive AI-based analysis tools, classifying the package as safe despite its malicious intent.

Broader Implications for the Developer Community

The Hades attack extends its reach to packages related to computational biology and bioinformatics, further illustrating the threat’s expansive nature. Packages like embiggen and gpsea are among those compromised, using the Bun runtime to execute the malicious JavaScript payload.

Security researchers emphasize that the Hades campaign’s capabilities include lateral spread across networks, targeting GitHub repositories, and exploiting developer trust configurations. The malware even includes a wiper feature named “gh-token-monitor,” which activates if a stolen GitHub token is revoked.

Conclusion and Future Outlook

This latest development in supply chain attacks highlights the vulnerability of open-source ecosystems, even with signed keys and authenticated accounts. As attackers become more sophisticated, developers must remain vigilant and proactive in securing their environments. The Hades campaign underscores the need for robust security practices and continuous monitoring to protect against evolving threats.

The Hacker News Tags:AI evasion, Bun runtime, credential stealer, Cybersecurity, developer security, GitHub, Hades attack, JavaScript payload, Malware, PyPI, Python packages, Software Security, supply chain attack, supply chain compromise

Post navigation

Previous Post: North Korean Hackers Exploit GitHub to Target Developers
Next Post: Anthropic Unveils Claude Fable 5: Secure Mythos-Class AI

Related Posts

Google Releases Critical Chrome Update for CVE-2025-6558 Exploit Active in the Wild Google Releases Critical Chrome Update for CVE-2025-6558 Exploit Active in the Wild The Hacker News
New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status The Hacker News
Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery The Hacker News
Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers The Hacker News
Critical PHP Composer Vulnerabilities Patched Critical PHP Composer Vulnerabilities Patched The Hacker News
Microsoft Addresses High-Severity Windows Admin Center Flaw Microsoft Addresses High-Severity Windows Admin Center Flaw The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Adobe Addresses 123 Security Flaws in Major Update
  • Meta Enhances AI with External Business Data
  • MagicAd Malware Bypasses Android Restrictions with Ads
  • Anthropic Unveils Claude Fable 5: Secure Mythos-Class AI
  • Hades Attack Targets PyPI: 19 Packages Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Adobe Addresses 123 Security Flaws in Major Update
  • Meta Enhances AI with External Business Data
  • MagicAd Malware Bypasses Android Restrictions with Ads
  • Anthropic Unveils Claude Fable 5: Secure Mythos-Class AI
  • Hades Attack Targets PyPI: 19 Packages Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark