# Over 100 NPM and PyPI Packages Compromised in Coordinated Shai-Hulud Supply Chain Attack Wave


Security researchers warn of surging variants, source code leaks, and self-propagating worms spreading across JavaScript and Python ecosystems


The open source software community faces an escalating threat from newly weaponized variants of the Shai-Hulud self-propagating worm. Since June 1, coordinated supply chain attacks have compromised over 100 packages across Node Package Manager (NPM) and Python Package Index (PyPI), with security researchers identifying at least 471 malicious artifacts across both ecosystems. The attacks underscore how the release of malware source code can rapidly accelerate threats to critical development infrastructure.


## The Current Threat Landscape


Over the past week, two distinct variants of Shai-Hulud—dubbed Miasma and Hades—have swept through major development ecosystems. According to research from Snyk, Sonatype, StepSecurity, and Socket, the attack represents a dramatic escalation of supply chain targeting:


| Attack Wave | Target Ecosystem | Packages Affected | Malicious Versions | Timeline |

|---|---|---|---|---|

| Miasma (NPM) | JavaScript/Node.js | 57+ | 300+ | June 1-5 |

| Hades Wave 1 (PyPI) | Python | 19 | Multiple | June 5-7 |

| Hades Wave 2 (PyPI) | Python | 29 | Multiple | June 8+ |

| Red Hat Incident | JavaScript | 32 | Multiple | Early June |


The attack impacted high-profile packages including the Vapi server SDK, ai-sdk-ollama, autotel, awaitly, executable-stories, node-env-resolver, and wrangler-deploy. PyPI victims included packages in bioinformatics, graph machine learning, and MCP-themed development tools.


## Background: The Evolution of Shai-Hulud


The Shai-Hulud worm is not new. Security researchers have tracked the self-replicating malware since September 2025, when it first appeared targeting the open source ecosystem. However, a critical inflection point occurred in mid-May 2026, when TeamPCP, the hacking group behind Shai-Hulud, publicly released the worm's source code.


The release proved catastrophic. Within days, clones and variants began appearing. The first major incident following the code leak was the Red Hat Hybrid Cloud Console attack, in which 32 packages in Red Hat's JavaScript ecosystem were infected, demonstrating that established organizations with secure supply chains were now targets.


This pattern—source code leak followed by rapid proliferation of variants—has become a defining characteristic of modern supply chain threats. The publication of functional malware code eliminates barriers to entry for less sophisticated threat actors and allows rapid adaptation and mutation of attacks.


## Technical Details: How Miasma and Hades Work


### Miasma: The NPM Variant


Miasma is a multi-stage dropper that executes during NPM package installation. Security researchers identified the payload by its telltale string: "Miasma: The Spreading Blight."


Attack mechanism:


  • Installation trigger: The malware uses a weaponized binding.gyp file designed to bypass standard postinstall execution logic while maintaining similar behavioral patterns
  • Reconnaissance: Upon execution, the worm scans the local system and connected cloud services for sensitive data—API keys, authentication tokens, credentials, and other secrets
  • Lateral movement: Using harvested credentials, the malware attempts to infect other packages accessible to the compromised developer
  • Persistence: By targeting packages in a developer's supply chain, Miasma achieves broad distribution across organizational ecosystems

  • The scope of the Miasma campaign was staggering: by June 5, researchers had catalogued at least 57 malicious NPM packages and over 300 malicious versions spreading variants of the worm.


    ### Hades: The PyPI Variant


    Hades, characterized by the string "Hades – The End for the Damned," is effectively the Python branch of Miasma, adapted for the PyPI ecosystem. The attack unfolded in two distinct waves:


    Wave 1 (June 5-7): Initial 19 packages

  • Payloads used *-setup.pth files to execute arbitrary code at Python startup
  • The worm fetched the Bun JavaScript runtime and executed JavaScript code within Python environments
  • This cross-language execution capability represents a sophisticated adaptation for polyglot development environments

  • Wave 2 (June 8+): 29 additional packages

  • Phantom releases were pushed to PyPI without corresponding updates on GitHub, making detection more difficult
  • Researchers identified a mutation in the execution chain: payloads are no longer bundled with the loader, instead searching across sys.path to split loader and payload functionality
  • This architectural change appears designed to evade signature-based detection tools

  • Both Hades waves retained the credential-harvesting and self-propagation mechanisms from Miasma, along with Shai-Hulud's established data exfiltration technique: publishing collected information to newly created GitHub repositories.


    ## Implications for Organizations


    The scale and sophistication of these attacks carry severe implications:


    ### Risk to Development Teams

    Developers who installed affected packages during vulnerability windows may have:

  • Compromised credentials (cloud API keys, GitHub tokens, database credentials)
  • Infected development environments capable of spreading the worm to all packages they publish
  • Lateral movement risks enabling attackers to infiltrate organizational cloud infrastructure and internal systems

  • ### Supply Chain Contamination

    The self-propagating nature of Miasma and Hades means victims become vectors. A developer whose environment is compromised may unknowingly publish infected packages, expanding the attack surface exponentially. This transforms isolated incidents into systemic ecosystem threats.


    ### Timing Concerns

    The surge of attacks following the TeamPCP source code leak suggests attackers are rapidly iterating and testing variants. The appearance of detection-evasion techniques in Hades Wave 2 (just days after Wave 1) indicates active refinement of attack methods.


    ## Recommendations for Defense


    ### Immediate Actions


    1. Audit package dependencies: Run dependency audits on all internal and external projects to identify affected packages. Check against the following known victims:

    - NPM: Vapi SDK, ai-sdk-ollama, autotel, awaitly, executable-stories, node-env-resolver, wrangler-deploy

    - PyPI: bioinformatics, graph machine learning, and MCP-themed packages from June 5-8


    2. Credential rotation: If any developer installed affected packages, assume potential credential compromise. Rotate:

    - GitHub personal access tokens and deploy keys

    - Cloud provider API keys (AWS, Azure, GCP)

    - Database credentials

    - Third-party service tokens


    3. Environment inspection: Conduct forensic analysis of development machines that may have installed malicious versions:

    - Check for unexpected processes, scheduled tasks, or startup scripts

    - Review outbound network connections during installation windows

    - Inspect .pth files (Python) and binding.gyp files (Node.js) for suspicious modifications


    ### Medium-Term Protections


  • Implement package pinning: Use exact versions rather than version ranges to prevent accidental installation of malicious updates
  • Enable code signing verification: Where supported, verify package signatures before installation
  • Establish isolated build environments: Consider containerized or virtualized build pipelines that limit lateral movement if compromise occurs
  • Monitor for suspicious package behavior: Tools like Snyk and Socket provide real-time detection of malicious payloads

  • ### Ecosystem-Level Advocacy


  • Encourage registry maintainers (npm, PyPI) to implement stronger verification mechanisms for package publishers
  • Support initiatives like Red Hat and IBM's Project Lightwell, which commits $5 billion to securing open source supply chains
  • Advocate for improved transparency in package publishing, including activity logs and deployment tracking

  • ---


    ## HackWire Analysis


    Why This Escalation Matters Now


    The Shai-Hulud variants represent a critical inflection point in supply chain attack maturity. What distinguishes Miasma and Hades from earlier incidents is the democratization of the attack vector. By releasing functional source code, TeamPCP eliminated the skill and resource barriers that previously limited supply chain attacks to sophisticated threat actors. Now, any group with basic development knowledge can rapidly adapt and deploy variants—which is exactly what we're seeing.


    The timing is particularly concerning: attacks accelerated immediately after source code release and continued to mutate in real-time (see the detection-evasion changes in Hades Wave 2). This suggests active adversary iteration, not passive exploitation of existing code. The split loader/payload architecture and cross-language execution capabilities (fetching Bun runtime from Python environments) show serious engineering effort aimed at evading automated detection.


    The Pattern We Should Recognize


    This follows a proven pattern: vulnerability disclosure → tool/code release → rapid commoditization → widespread adoption. We've seen it before with browser exploits, network tools, and exploit frameworks. Supply chain attacks are now mature enough to follow the same trajectory. The next threat should assume that source code will leak, and attacks will proliferate.


    What Defenders Are Missing


    Most incident response focuses on identifying and patching affected packages. That's necessary but insufficient. The real risk is lateral spread within organizational cloud environments. Developers' credentials are gateway credentials—they unlock CI/CD pipelines, cloud accounts, and internal repositories. An attacker with harvested developer credentials doesn't need to continue spreading through package ecosystems; they can pivot directly to infrastructure. Organizations should focus forensic effort on cloud activity during compromise windows, not just package activity.


    Concrete Next Step


    Teams should treat affected package installations as credential-compromise incidents requiring full rotation of developer secrets, not just package updates. This is not a patch-and-move-on scenario—assume breach, rotate, audit.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)