<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Over 100 NPM and PyPI Packages Infected in Escalating Shai-Hulud Supply Chain Attacks

Self-replicating worm Shai-Hulud infects 100+ NPM and PyPI packages with new variants Miasma and Hades targeting credentials and SDKs.
Content Team

A self-replicating worm called Shai-Hulud has infected over 100 packages across NPM and PyPI since September 2025, with attacks sharply escalating in recent weeks. After hacking group TeamPCP released the worm's source code in mid-May, clones emerged fast.

The latest variants — Miasma and Hades — harvest credentials, API keys, and tokens, then spread by infecting packages the victim can access. Red Hat's Hybrid Cloud Console was among the targets, alongside SDKs like Vapi and Wrangler. In total, 471 malicious artifacts have been identified, including PyPI wheel files tied to the Hades branch.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo