Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hades Attack Targets PyPI: 19 Packages Compromised

Hades Attack Targets PyPI: 19 Packages Compromised

Posted on June 9, 2026 By CWS

The recent emergence of the Hades attack signifies a new chapter in the ongoing saga of supply chain threats, specifically targeting the Python Package Index (PyPI). This campaign involves 37 malicious wheel artifacts spread across 19 different packages, reflecting a refinement of the earlier Mini Shai-Hulud-style operations. The key focus remains on exploiting specific ecosystems through compromised packages.

Understanding the Hades Attack Mechanism

The Hades attack involves the deployment of a malicious *-setup.pth file, which is designed to execute during Python startup. This file downloads the Bun JavaScript runtime and initiates an obfuscated JavaScript payload. Unlike previous campaigns, this payload does not require the victim to import the compromised package, making it particularly insidious.

Once activated, the payload can harvest a broad spectrum of sensitive information, including credentials from platforms such as GitHub, npm, and AWS. These credentials are then utilized to facilitate further exploitation and propagation of the malware.

Noteworthy Changes and Techniques

A significant shift in the Hades campaign is the use of the *-setup.pth file, enabling the payload to execute without user intervention. Previously, harvested data was exported to public GitHub repositories under the name ‘Miasma: The Spreading Blight.’ However, the current campaign utilizes descriptors like ‘Hades – The End for the Damned,’ marking a new phase in its evolution.

The attack also includes a novel approach to misleading AI security scanners. By embedding an entry point in the package’s “__init__.py” file, the malware employs a plain-text prompt injection to deceive AI-based analysis tools, classifying the package as safe despite its malicious intent.

Broader Implications for the Developer Community

The Hades attack extends its reach to packages related to computational biology and bioinformatics, further illustrating the threat’s expansive nature. Packages like embiggen and gpsea are among those compromised, using the Bun runtime to execute the malicious JavaScript payload.

Security researchers emphasize that the Hades campaign’s capabilities include lateral spread across networks, targeting GitHub repositories, and exploiting developer trust configurations. The malware even includes a wiper feature named “gh-token-monitor,” which activates if a stolen GitHub token is revoked.

Conclusion and Future Outlook

This latest development in supply chain attacks highlights the vulnerability of open-source ecosystems, even with signed keys and authenticated accounts. As attackers become more sophisticated, developers must remain vigilant and proactive in securing their environments. The Hades campaign underscores the need for robust security practices and continuous monitoring to protect against evolving threats.

The Hacker News Tags:AI evasion, Bun runtime, credential stealer, Cybersecurity, developer security, GitHub, Hades attack, JavaScript payload, Malware, PyPI, Python packages, Software Security, supply chain attack, supply chain compromise

Post navigation

Previous Post: North Korean Hackers Exploit GitHub to Target Developers
Next Post: Anthropic Unveils Claude Fable 5: Secure Mythos-Class AI

Related Posts

Webinar Reveals Strategies Against Stealth Cyber Breaches Webinar Reveals Strategies Against Stealth Cyber Breaches The Hacker News
LiteLLM Vulnerability Allows Server Takeover LiteLLM Vulnerability Allows Server Takeover The Hacker News
Veeam Fixes Critical Flaws in Backup Software Veeam Fixes Critical Flaws in Backup Software The Hacker News
SEC Files Charges Over  Million Crypto Scam Using Fake AI-Themed Investment Tips SEC Files Charges Over $14 Million Crypto Scam Using Fake AI-Themed Investment Tips The Hacker News
How CISOs Can Drive Effective AI Governance How CISOs Can Drive Effective AI Governance The Hacker News
CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark