Miasma Worm Campaign Spreads with New PyPI Wave
Essential information
- Published
- 07/06/2026 11:21
- Modified
- 08/06/2026 09:23
- Tags
- 2026-06-07 bioinformatics bun runtime credential-theft github exfiltration hades miasma mini shai hulud pypi startup hooks supply chain attack
- Related entities
- 3 observables, 1 intrusion sets (apt), 3 malware, 2 others
Description
A coordinated PyPI compromise campaign involving 37 malicious wheel artifacts across 19 packages was detected, utilizing Python startup hooks to execute credential-stealing payloads. The attack leverages .pth files for automatic execution during Python interpreter startup, downloads the Bun JavaScript runtime, and runs obfuscated JavaScript payloads. The malware targets high-value developer and CI/CD credentials including GitHub, npm, PyPI, cloud providers (AWS, GCP, Azure), Kubernetes, Vault, SSH keys, and AI tool tokens. This represents a PyPI branch of the Shai-Hulud/Miasma campaign family, using a Hades-themed variant for GitHub exfiltration. Compromised packages included established bioinformatics tools with significant download counts, stemming from apparent maintainer account takeover. The payload employs multi-layer obfuscation, AES-GCM encryption, and exfiltrates data through GitHub repositories with distinctive markers. The campaign demonstrates cross-runtime attack capabilities and ecosystem-spe...