Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels
Essential information
- Published
- 08/06/2026 21:36
- Modified
- 09/06/2026 08:57
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- bioinformatics bun runtime ci/cd compromise credential theft hades javascript stealer mcp developers miasma mini shai-hulud native extensions pypi supply chain attack typosquatting
- Tags
- 2026-06-08 bioinformatics bun runtime ci/cd compromise credential-theft hades javascript stealer mcp developers miasma mini shai hulud native extensions pypi supply chain attack typosquatting
- Related entities
- 2 indicators, 2 observables, 19 techniques (mitre), 3 malware, 1 others
Description
A sophisticated supply chain attack campaign has expanded to 471 affected artifacts across npm and PyPI, targeting developers through malicious packages. The campaign uses three distinct delivery methods: executable .pth startup hooks, trojanized native .abi3.so extensions that execute at import time, and a split loader-payload architecture that searches Python's sys.path. Twenty-three newly identified PyPI packages masquerade as bioinformatics tools, AI frameworks, and popular libraries like requests and Flask. The attack deploys heavily obfuscated JavaScript stealers via Bun runtime, harvesting high-value credentials including GitHub tokens, npm registry access, cloud credentials, SSH keys, and CI/CD secrets. The malware employs anti-analysis techniques with fake LLM prompt-injection headers designed to disrupt AI-assisted security scanners, while targeting developer workstations and automated build environments.