Over 100 NPM and PyPI Packages Infected in Escalating Shai-Hulud Supply Chain Attacks
Want more insights like this?
A self-replicating worm called Shai-Hulud has infected over 100 packages across NPM and PyPI since September 2025, with attacks sharply escalating in recent weeks. After hacking group TeamPCP released the worm's source code in mid-May, clones emerged fast — Socket, Snyk, Sonatype, Ox Security and others have been tracking the fallout since.
The latest variants — Miasma and Hades — harvest credentials, API keys and tokens, then spread by infecting packages the victim can access. Miasma drops via weaponized binding.gyp files during npm install; Hades uses -setup.pth files to run at Python startup, pulling in the Bun runtime to execute. Red Hat's Hybrid Cloud Console lost 32 JavaScript packages, alongside the Vapi server SDK and wrangler-deploy, with Hades leaning on bioinformatics, graph ML and MCP-themed packages.
In total, 471 malicious artifacts have been identified. If you've installed anything from these ecosystems recently, rotate your npm, PyPI and cloud credentials — the worm spreads using what it steals.
Source: SecurityWeek