Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
2,072
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Socket Threat Research team has identified a new wave of supply chain attacks involving malicious PyPI packages that expand on previous campaigns like Mini Shai-Hulud, Miasma, and Hades. This latest wave includes 23 newly identified PyPI artifacts, featuring bioinformatics packages, typosquat-style packages, and AI-themed packages. The threat actors are rapidly evolving their tactics, employing diverse delivery mechanisms such as .pth startup hooks, trojanized native extensions, and payload discovery across Python’s sys.path. A notable variant, langchain-core-mcp, separates the loader from the payload, complicating detection efforts. The campaign targets developer workstations and CI/CD environments to steal valuable credentials and secrets. The malicious packages are part of a broader supply chain attack strategy that continues to adapt, making it crucial for defenders to focus on execution paths and credential exposure while employing robust detection and response measures.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 27 7,550 833 207 +6%
LLM 4 6,196 1,155 243 -32%
Secrets Management 2 2,476 387 132 +15%
Kubernetes 1 2,148 318 105 +9%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.