# PyPI Under Siege: Hades Campaign Poisons 19 Packages in Latest Supply Chain Attack


A sophisticated supply chain attack has compromised 19 packages across the Python Package Index (PyPI), distributing 37 malicious wheel artifacts designed to harvest sensitive credentials from developer machines and CI/CD environments. The campaign, tracked as "Hades," represents the latest evolution of the Miasma supply chain attack lineage and demonstrates how attackers continue to refine their techniques for evading detection while maximizing impact.


According to analysis by Socket, the compromised packages were configured to execute malicious code automatically during Python interpreter startup, bypassing the need for developers to actually import the poisoned modules. This execution mechanism represents a critical escalation in supply chain attack sophistication, as it guarantees payload delivery regardless of how the package is installed.


## The Threat: Automated Credential Theft at Scale


The Hades campaign delivers a credential stealer that targets an extensive list of developer tools and cloud platforms, including:


Targeted Credentials and Secrets:

  • Source Control & Package Management: GitHub, npm, PyPI, RubyGems, JFrog
  • CI/CD Platforms: CircleCI
  • AI/ML Services: Anthropic
  • Cloud Providers: AWS, GCP, Azure
  • Container Orchestration: Kubernetes, Docker
  • Development Tools: SSH keys, shell histories, .env files, .npmrc files, .pypirc files, Vault tokens

  • The breadth of targeted credentials indicates sophisticated threat actors who understand the typical security infrastructure of modern software development teams. The inclusion of Anthropic in the target list is particularly notable given the company's role in AI infrastructure.


    The payload also targets Claude/MCP configurations, suggesting attackers are specifically aware of tools used in AI-integrated development environments. This level of specificity points to threat actors with deep knowledge of contemporary development practices.


    ## Background and Context: The Miasma Lineage


    The Hades campaign is not an isolated incident but rather the latest manifestation of an ongoing attack series that includes two previous campaigns: Shai-Hulud and Miasma. According to Socket, Hades should be understood as a PyPI-specific branch of the same threat actor operation, distinguished primarily by campaign markers and slight methodological variations.


    The Attack Lineage:


    | Campaign | Year | Focus | Method | Exfiltration |

    |----------|------|-------|--------|--------------|

    | Shai-Hulud | 2024 | npm ecosystem | Install hooks | GitHub repos |

    | Miasma | 2025 | Multiple packages | Install hooks | GitHub repos |

    | Hades | 2026 | PyPI + bioinformatics | setup.pth files | GitHub repos |


    What distinguishes Hades from its predecessors is the shift from npm's install hooks to Python's setup.pth mechanism—a technique that provides even more reliable code execution. The campaign marker changed from "Miasma: The Spreading Blight" to "Hades - The End for the Damned," but the core attack playbook remains consistent.


    This continuity suggests sustained funding and operational capability from the threat actors, implying this is not opportunistic malware but rather a coordinated, long-term campaign against developer supply chains.


    ## Technical Details: The Execution Mechanism


    The Hades campaign employs two distinct technical approaches, indicating either multiple threat actors within the same campaign or deliberate variant deployment for redundancy and evasion purposes.


    ### Variant 1: The setup.pth Approach (Primary Method)


    The primary variant uses Python's site-packages initialization mechanism:


    1. Installation Phase: The malicious wheel artifact is installed normally via pip install

    2. Payload Placement: A *-setup.pth file is placed in the site-packages directory

    3. Execution Trigger: During Python interpreter startup, the site module automatically processes .pth files and executes any code within them

    4. Payload Download: The code downloads the Bun JavaScript runtime from GitHub

    5. Stealer Execution: An obfuscated JavaScript stealer (_index.js) runs within the Bun runtime

    6. Credential Harvesting: The stealer collects credentials from the developer environment

    7. Data Exfiltration: Harvested data is sent to attacker-controlled GitHub repositories


    As Socket notes, this is "the Python equivalent of the npm install-hook problem." The critical distinction is that the malicious code executes after installation but before the package is imported by application code, creating an execution window where normal security review procedures fail.


    ### Variant 2: The __init__.py Approach (Bioinformatics Targets)


    A secondary variant, observed in packages targeting computational biology and bioinformatics, embeds the malicious code directly in the package's __init__.py file as an obfuscated single-line import hook. This approach leverages the requirement to import the module, but the obfuscation makes detection more difficult.


    ### Locale Checking: Evasion Technique


    Both variants include a check for Russian locale (ru_RU), suggesting either:

  • Geographic targeting: The attackers may be based in Russia and avoiding compromising local systems
  • Evasion against local security researchers: Many Russian security researchers actively analyze malware, making this a logical exclusion

  • This detail indicates threat actors with operational security awareness.


    ## Affected Packages: The Scope


    The campaign compromised 19 distinct packages across two clusters:


    Cluster 1 - General Development Tools (11 packages, 19 variants):

    bramin, cmd2func, coolbox, dynamo-release, executor-engine, executor-http, funcdesc, magique, magique-ai, mrbios, napari-ufish, nucbox, okite, pantheon-agents, pantheon-toolsets, spateo-release, synago, ufish, uprobe


    Cluster 2 - Bioinformatics & Computational Biology (7 packages):

    embiggen, ensmallen, gpsea, mflux-streamlit, nhmpy, ppkt2synergy, pyphetools


    The targeting of bioinformatics packages is strategically significant. These tools are used by researchers at universities, pharmaceutical companies, and biotech firms—organizations whose intellectual property and research data are high-value targets. A compromise of these packages could provide attackers with access to early-stage drug research, genomic analysis tools, and proprietary biological datasets.


    ## Implications: Who Is Affected?


    The attack surface extends across multiple constituencies:


    Individual Developers: Any developer who installed affected package versions has potentially had their local credentials stolen, including API keys, SSH keys, and authentication tokens.


    Organizations: Companies whose developers installed these packages face potential compromise of:

  • Source code repositories
  • Cloud infrastructure credentials
  • Deployment pipelines
  • Development databases and caches

  • Academic and Research Institutions: The bioinformatics cluster targets organizations conducting sensitive research, potentially exposing unpublished research data.


    Supply Chain Cascade: Developers who installed these packages may have propagated the compromise further downstream through their own published packages or internal tools.


    ## Recommendations: Immediate Actions


    For Individual Developers:

    1. Audit package installations — Check pip history for any of the 19 affected packages

    2. Rotate all credentials immediately — GitHub, npm, PyPI, AWS, GCP, Azure, and any other platform where credentials may have been stored

    3. Review Git logs — Check for any suspicious commits or repository changes

    4. Scan systems — Look for suspicious processes, particularly any spawning Bun runtimes

    5. Notify employers — If the affected package was installed in a professional context, escalate to security teams


    For Organizations:

    1. Audit development environments — Scan all developer machines and CI/CD systems for Bun runtime installations

    2. Conduct credential audit — Verify that no unauthorized access occurred to cloud platforms or repositories

    3. Review logs — Check Git, cloud provider logs, and package registry logs for suspicious activity

    4. Implement package security scanning — Deploy tools that detect malicious packages before installation

    5. Restrict PyPI access — Use private package mirrors to pre-scan packages before internal distribution

    6. Monitor GitHub — Check for exfiltrated credentials appearing in repositories


    Going Forward:

  • Require signed packages: Push for mandatory digital signatures on PyPI packages
  • Implement SBOM requirements: Track all dependencies and their integrity
  • Deploy runtime monitoring: Monitor Python startup and JavaScript execution in production environments

  • ---


    ## HackWire Analysis


    The Hades campaign represents a maturation of supply chain attack tactics that goes beyond opportunistic malware distribution. The sustained focus across multiple ecosystems—npm, PyPI, and now bioinformatics—combined with evolving evasion techniques, suggests this is a state-level or well-resourced threat operation.


    What's particularly concerning is the execution guarantee provided by the setup.pth mechanism. Unlike traditional package installation that requires code invocation, this attack executes automatically after installation. This eliminates the developer's opportunity to review the code before it runs, fundamentally undermining the "peer review as security control" assumption that the open-source community relies on.


    The targeting of bioinformatics packages reveals how supply chain attacks are becoming *strategically selective*. Rather than broadly compromising high-download-count packages, attackers are now identifying vertical-specific tools that reach valuable targets: academic researchers, pharmaceutical companies, biotech firms. This is intelligence-driven targeting.


    The inclusion of Anthropic and Claude/MCP configurations in the credential targets is worth examining. As AI tooling becomes integrated into developer workflows, attackers are adapting their credential harvesting to match. This suggests a threat landscape where AI-assisted development is now mainstream enough to be explicitly targeted by sophisticated malware.


    The locale check for Russian systems raises questions about threat actor geography or operational practices, but defenders should not assume this provides protection for non-Russian targets—if anything, it suggests the attackers have sufficient sophistication to implement basic environmental checks, making them more dangerous overall.


    For defenders, the lesson is clear: trusting package registries is no longer sufficient. Organizations must assume that popular open-source repositories will be compromised and implement defense-in-depth: package signature verification, runtime monitoring, credential isolation, and principle-of-least-privilege access controls. The era of "just run pip install" is over.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)