Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AI'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud
A new malware campaign dubbed 'Hades' has targeted the Python Package Index (PyPI), compromising 37 wheel distributions and 19 code packages. This attack represents an evolution of the Shai-Hulud threat, demonstrating the ongoing sophistication of software supply chain attacks targeting open-source repositories.
AIFake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
Cybersecurity researchers have identified a large-scale malicious campaign using fake websites that impersonate legitimate open-source and freeware projects. These fraudulent sites, which rank highly on Google search results, redirect users through a Traffic Distribution System (TDS) to deliver malware including Remus Stealer, AnimateClipper, and SessionGate framework. The sites are professionally
