# Over 100 NPM and PyPI Packages Compromised in Coordinated Shai-Hulud Supply Chain Attack Wave
Security researchers warn of surging variants, source code leaks, and self-propagating worms spreading across JavaScript and Python ecosystems
The open source software community faces an escalating threat from newly weaponized variants of the Shai-Hulud self-propagating worm. Since June 1, coordinated supply chain attacks have compromised over 100 packages across Node Package Manager (NPM) and Python Package Index (PyPI), with security researchers identifying at least 471 malicious artifacts across both ecosystems. The attacks underscore how the release of malware source code can rapidly accelerate threats to critical development infrastructure.
## The Current Threat Landscape
Over the past week, two distinct variants of Shai-Hulud—dubbed Miasma and Hades—have swept through major development ecosystems. According to research from Snyk, Sonatype, StepSecurity, and Socket, the attack represents a dramatic escalation of supply chain targeting:
| Attack Wave | Target Ecosystem | Packages Affected | Malicious Versions | Timeline |
|---|---|---|---|---|
| Miasma (NPM) | JavaScript/Node.js | 57+ | 300+ | June 1-5 |
| Hades Wave 1 (PyPI) | Python | 19 | Multiple | June 5-7 |
| Hades Wave 2 (PyPI) | Python | 29 | Multiple | June 8+ |
| Red Hat Incident | JavaScript | 32 | Multiple | Early June |
The attack impacted high-profile packages including the Vapi server SDK, ai-sdk-ollama, autotel, awaitly, executable-stories, node-env-resolver, and wrangler-deploy. PyPI victims included packages in bioinformatics, graph machine learning, and MCP-themed development tools.
## Background: The Evolution of Shai-Hulud
The Shai-Hulud worm is not new. Security researchers have tracked the self-replicating malware since September 2025, when it first appeared targeting the open source ecosystem. However, a critical inflection point occurred in mid-May 2026, when TeamPCP, the hacking group behind Shai-Hulud, publicly released the worm's source code.
The release proved catastrophic. Within days, clones and variants began appearing. The first major incident following the code leak was the Red Hat Hybrid Cloud Console attack, in which 32 packages in Red Hat's JavaScript ecosystem were infected, demonstrating that established organizations with secure supply chains were now targets.
This pattern—source code leak followed by rapid proliferation of variants—has become a defining characteristic of modern supply chain threats. The publication of functional malware code eliminates barriers to entry for less sophisticated threat actors and allows rapid adaptation and mutation of attacks.
## Technical Details: How Miasma and Hades Work
### Miasma: The NPM Variant
Miasma is a multi-stage dropper that executes during NPM package installation. Security researchers identified the payload by its telltale string: "Miasma: The Spreading Blight."
Attack mechanism:
binding.gyp file designed to bypass standard postinstall execution logic while maintaining similar behavioral patternsThe scope of the Miasma campaign was staggering: by June 5, researchers had catalogued at least 57 malicious NPM packages and over 300 malicious versions spreading variants of the worm.
### Hades: The PyPI Variant
Hades, characterized by the string "Hades – The End for the Damned," is effectively the Python branch of Miasma, adapted for the PyPI ecosystem. The attack unfolded in two distinct waves:
Wave 1 (June 5-7): Initial 19 packages
*-setup.pth files to execute arbitrary code at Python startupWave 2 (June 8+): 29 additional packages
sys.path to split loader and payload functionalityBoth Hades waves retained the credential-harvesting and self-propagation mechanisms from Miasma, along with Shai-Hulud's established data exfiltration technique: publishing collected information to newly created GitHub repositories.
## Implications for Organizations
The scale and sophistication of these attacks carry severe implications:
### Risk to Development Teams
Developers who installed affected packages during vulnerability windows may have:
### Supply Chain Contamination
The self-propagating nature of Miasma and Hades means victims become vectors. A developer whose environment is compromised may unknowingly publish infected packages, expanding the attack surface exponentially. This transforms isolated incidents into systemic ecosystem threats.
### Timing Concerns
The surge of attacks following the TeamPCP source code leak suggests attackers are rapidly iterating and testing variants. The appearance of detection-evasion techniques in Hades Wave 2 (just days after Wave 1) indicates active refinement of attack methods.
## Recommendations for Defense
### Immediate Actions
1. Audit package dependencies: Run dependency audits on all internal and external projects to identify affected packages. Check against the following known victims:
- NPM: Vapi SDK, ai-sdk-ollama, autotel, awaitly, executable-stories, node-env-resolver, wrangler-deploy
- PyPI: bioinformatics, graph machine learning, and MCP-themed packages from June 5-8
2. Credential rotation: If any developer installed affected packages, assume potential credential compromise. Rotate:
- GitHub personal access tokens and deploy keys
- Cloud provider API keys (AWS, Azure, GCP)
- Database credentials
- Third-party service tokens
3. Environment inspection: Conduct forensic analysis of development machines that may have installed malicious versions:
- Check for unexpected processes, scheduled tasks, or startup scripts
- Review outbound network connections during installation windows
- Inspect .pth files (Python) and binding.gyp files (Node.js) for suspicious modifications
### Medium-Term Protections
### Ecosystem-Level Advocacy
---
## HackWire Analysis
Why This Escalation Matters Now
The Shai-Hulud variants represent a critical inflection point in supply chain attack maturity. What distinguishes Miasma and Hades from earlier incidents is the democratization of the attack vector. By releasing functional source code, TeamPCP eliminated the skill and resource barriers that previously limited supply chain attacks to sophisticated threat actors. Now, any group with basic development knowledge can rapidly adapt and deploy variants—which is exactly what we're seeing.
The timing is particularly concerning: attacks accelerated immediately after source code release and continued to mutate in real-time (see the detection-evasion changes in Hades Wave 2). This suggests active adversary iteration, not passive exploitation of existing code. The split loader/payload architecture and cross-language execution capabilities (fetching Bun runtime from Python environments) show serious engineering effort aimed at evading automated detection.
The Pattern We Should Recognize
This follows a proven pattern: vulnerability disclosure → tool/code release → rapid commoditization → widespread adoption. We've seen it before with browser exploits, network tools, and exploit frameworks. Supply chain attacks are now mature enough to follow the same trajectory. The next threat should assume that source code will leak, and attacks will proliferate.
What Defenders Are Missing
Most incident response focuses on identifying and patching affected packages. That's necessary but insufficient. The real risk is lateral spread within organizational cloud environments. Developers' credentials are gateway credentials—they unlock CI/CD pipelines, cloud accounts, and internal repositories. An attacker with harvested developer credentials doesn't need to continue spreading through package ecosystems; they can pivot directly to infrastructure. Organizations should focus forensic effort on cloud activity during compromise windows, not just package activity.
Concrete Next Step
Teams should treat affected package installations as credential-compromise incidents requiring full rotation of developer secrets, not just package updates. This is not a patch-and-move-on scenario—assume breach, rotate, audit.
— HackWire Editorial
---
## Related Coverage