Shai-Hulud "Hades" Wave Hits Six PyPI Bioinformatics Packages via Stolen Tokens
Blog post from Endor Labs
On June 8, 2026, a sophisticated cyberattack targeted the PyPI ecosystem, where six Python packages related to academic genomics and machine learning were replaced with trojanized versions containing a credential-stealing worm. These packages, widely used in university research groups and biotech companies, were released as phantom versions without corresponding GitHub commits. The attack utilized a custom JavaScript automation script to bypass standard CI/CD pipelines and embedded the malicious payload within compiled Rust/C++ binary extensions, enabling execution when Python called the package. A multi-stage operation, it involved a JavaScript loader with evasion techniques, a Bun runtime to avoid detection, and a credential theft mechanism targeting major cloud platforms, password managers, and AI coding tools. The stolen data was exfiltrated through covert GitHub repositories, and the worm further propagated by publishing compromised packages to npm and RubyGems. It also forged SLSA provenance to mask the attack, targeted CI environments, and facilitated lateral movement through SSH. The campaign highlights the need for enhanced security measures in package distribution, emphasizing the importance of forensic indicators such as the Bun/1.3.13 signature for future threat detection.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 15 | 2,515 | 393 | 134 | +17% |
| AI Coding Assistant | 5 | 2,161 | 541 | 167 | +20% |
| Kubernetes | 4 | 2,168 | 322 | 107 | +10% |
| LLM | 1 | 6,237 | 1,165 | 246 | -31% |
| Vector Search | 1 | 1,897 | 384 | 134 | -16% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.