Miasma Worm Campaign Spreads with New PyPI Wave

June 8, 2026, 9:23 a.m.

Description

A coordinated PyPI compromise campaign involving 37 malicious wheel artifacts across 19 packages was detected, utilizing Python startup hooks to execute credential-stealing payloads. The attack leverages .pth files for automatic execution during Python interpreter startup, downloads the Bun JavaScript runtime, and runs obfuscated JavaScript payloads. The malware targets high-value developer and CI/CD credentials including GitHub, npm, PyPI, cloud providers (AWS, GCP, Azure), Kubernetes, Vault, SSH keys, and AI tool tokens. This represents a PyPI branch of the Shai-Hulud/Miasma campaign family, using a Hades-themed variant for GitHub exfiltration. Compromised packages included established bioinformatics tools with significant download counts, stemming from apparent maintainer account takeover. The payload employs multi-layer obfuscation, AES-GCM encryption, and exfiltrates data through GitHub repositories with distinctive markers. The campaign demonstrates cross-runtime attack capabilities and ecosystem-spe...

Date

  • Created: June 7, 2026, 11:21 a.m.
  • Published: June 7, 2026, 11:21 a.m.
  • Modified: June 8, 2026, 9:23 a.m.

Indicators

  • c539766062555d47716f8432e73adbe3a0c0c954a0b6c4005017a668975e275c
  • e1342a80d4b5e83d2c7c22e1e0aaa95f2d88e3dbf0d853a4994b180c93a4b17d
  • dc48b09b2a5954f7ff79ab8a2fd80202bd3b59c08c7cdbc6025aa923cb4c0efe

Attack Patterns

  • Mini Shai-Hulud
  • Hades
  • Miasma
  • Shai-Hulud

Additional Informations

  • Technology
  • Healthcare