Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
2,293
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

A coordinated attack on the Python Package Index (PyPI) involved the compromise of 37 malicious wheel artifacts across 19 packages, utilizing a setup.pth file to execute a JavaScript payload via the Bun runtime during Python startup. This attack, identified by Socket's AI malware detection system, is part of the Shai-Hulud/Miasma lineage, characterized by its cross-runtime capabilities and sophisticated obfuscation techniques. The payload targets sensitive developer and CI/CD credentials, leveraging GitHub for exfiltration with new Hades-themed markers. This incident highlights the vulnerabilities in trusted package channels, as attackers exploited Python's .pth file execution to trigger malicious activities upon installation. The attack affected established bioinformatics tools and underscores the need for vigilance in managing dependencies and credentials across ecosystems. PyPI has quarantined some compromised releases, and affected organizations are advised to remove malicious versions, rebuild environments, and rotate credentials to mitigate potential damage.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 14 2,476 387 132 +15%
MCP 6 7,550 833 207 +6%
AI Coding Assistant 4 2,151 535 165 +20%
Kubernetes 3 2,148 318 105 +9%
LLM 1 6,196 1,155 243 -32%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.