Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Shai-Hulud Supply Chain Attacks Target NPM and PyPI Packages

Shai-Hulud Supply Chain Attacks Target NPM and PyPI Packages

Posted on June 9, 2026 By CWS

Recent Shai-Hulud supply chain attacks have affected more than 100 packages within the NPM and PyPI ecosystems, as reported by cybersecurity experts. These attacks, active since September 2025, have targeted open source software communities with increasing frequency, particularly after the Trivy vulnerability scanner incident.

Surge in Attacks Since May

In May, the hacking group TeamPCP released the source code for Shai-Hulud, leading to the emergence of new clones. By June 1, updated variants were used in expansive, organized attacks, starting with the Red Hat incident, which compromised 32 packages in the Hybrid Cloud Console JavaScript ecosystem.

The attacks have evolved, introducing the ‘Miasma’ variant, which was highlighted by the inclusion of the phrase “Miasma: The Spreading Blight” in the payload. Security firm Ox Security found several malicious NPM packages containing a weaponized binding.gyp file designed to circumvent standard execution procedures.

Miasma Variant Characteristics

Miasma, a descendant of the Mini Shai-Hulud, operates as a multi-stage dropper initiated during NPM package installation. According to Harness, it scans systems and cloud services for sensitive information like credentials and API keys, using this data to further propagate the attack.

By June 5, entities such as Snyk, Sonatype, and StepSecurity identified 57 affected NPM packages and over 300 malicious package versions linked to Miasma. The attacks have impacted several ecosystems including Vapi server SDK and ai-sdk-ollama.

Emergence of the Hades Variant

Following the Miasma attacks, researchers detected another Shai-Hulud variant named ‘Hades’ in roughly two dozen PyPI packages. This variant, marked by the string “Hades – The End for the Damned,” was discovered in an initial set of 19 packages, employing a *-setup.pth file to execute code upon Python startup.

Socket reports that Hades is essentially the PyPI branch of Miasma, exhibiting similar credential-harvesting and spreading tactics. On June 8, a second wave targeted more PyPI packages, with phantom releases appearing on PyPI without corresponding GitHub versions, affecting at least 29 packages according to StepSecurity.

The attacks have involved a total of 471 malicious artifacts across NPM and PyPI, including numerous harmful PyPI wheel artifacts related to the Hades Mini Shai-Hulud worm.

As these attacks continue to evolve, the cybersecurity community remains vigilant in addressing the vulnerabilities in open source supply chains. The incidents underscore the necessity for enhanced security measures to protect against such sophisticated threats.

Security Week News Tags:Cybersecurity, Hades, Malware, Miasma, NPM, open source security, OSS, PyPI, Shai-Hulud, supply chain attacks, TeamPCP

Post navigation

Previous Post: Unveiling the Hidden Risks in Network Security Operations
Next Post: Phishing Scams Exploit AI Tool Brands for Credential Theft

Related Posts

ShinyHunters Allegedly Breaches Council of Europe ShinyHunters Allegedly Breaches Council of Europe Security Week News
Critical Vulnerability Threatens 300,000 Ollama Deployments Critical Vulnerability Threatens 300,000 Ollama Deployments Security Week News
Unpatched Tenda Firmware Backdoor Risks Device Security Unpatched Tenda Firmware Backdoor Risks Device Security Security Week News
Critical Linux Flaw ‘Pack2TheRoot’ Grants Root Access Critical Linux Flaw ‘Pack2TheRoot’ Grants Root Access Security Week News
React Native Aria Packages Backdoored in Supply Chain Attack React Native Aria Packages Backdoored in Supply Chain Attack Security Week News
Is AI Use in the Workplace Out of Control? Is AI Use in the Workplace Out of Control? Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark