216.73.217.80

Miasma Worm Campaign Spreads with New PyPI Wave

· Published 07/06/2026 11:21 · Modified 08/06/2026 09:23

Export JSON

Essential information

Published
07/06/2026 11:21
Modified
08/06/2026 09:23
Tags
2026-06-07 bioinformatics bun runtime credential-theft github exfiltration hades miasma mini shai hulud pypi startup hooks supply chain attack
Related entities
3 observables, 1 intrusion sets (apt), 3 malware, 2 others

Description

A coordinated compromise campaign involving 37 malicious wheel artifacts across 19 packages was detected, utilizing Python to execute credential-stealing payloads. The attack leverages .pth files for automatic execution during Python interpreter startup, downloads the Bun JavaScript runtime, and runs obfuscated JavaScript payloads. The malware targets high-value developer and CI/CD credentials including GitHub, npm, , cloud providers (AWS, GCP, Azure), Kubernetes, Vault, SSH keys, and AI tool tokens. This represents a branch of the Shai-Hulud/ campaign family, using a -themed variant for . Compromised packages included established tools with significant download counts, stemming from apparent maintainer account takeover. The payload employs multi-layer obfuscation, AES-GCM encryption, and exfiltrates data through GitHub repositories with distinctive markers. The campaign demonstrates cross-runtime attack capabilities and ecosystem-spe...

External references