216.73.216.6

Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels

· Published 08/06/2026 21:36 · Modified 09/06/2026 08:57

Export JSON

Essential information

Published
08/06/2026 21:36
Modified
09/06/2026 08:57
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
bioinformatics bun runtime ci/cd compromise credential theft hades javascript stealer mcp developers miasma mini shai-hulud native extensions pypi supply chain attack typosquatting
Tags
2026-06-08 bioinformatics bun runtime ci/cd compromise credential-theft hades javascript stealer mcp developers miasma mini shai hulud native extensions pypi supply chain attack typosquatting
Related entities
2 indicators, 2 observables, 19 techniques (mitre), 3 malware, 1 others

Description

A sophisticated campaign has expanded to 471 affected artifacts across npm and , targeting developers through malicious packages. The campaign uses three distinct delivery methods: executable .pth startup hooks, trojanized native .abi3.so extensions that execute at import time, and a split loader-payload architecture that searches Python's sys.path. Twenty-three newly identified packages masquerade as tools, AI frameworks, and popular libraries like requests and Flask. The attack deploys heavily obfuscated JavaScript stealers via , harvesting high-value credentials including GitHub tokens, npm registry access, cloud credentials, SSH keys, and CI/CD secrets. The malware employs anti-analysis techniques with fake LLM prompt-injection headers designed to disrupt AI-assisted security scanners, while targeting developer workstations and automated build environments.

External references