Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIHades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
A new supply chain attack called Hades has compromised 19 packages in the Python Package Index (PyPI) registry, deploying 37 malicious wheel artifacts designed to automatically execute credential-stealing malware. This attack represents an evolution of the Miasma campaign, using *-setup.pth files for automatic execution and demonstrating increasingly sophisticated targeting of specific development
AI'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud
A new malware campaign dubbed 'Hades' has targeted the Python Package Index (PyPI), compromising 37 wheel distributions and 19 code packages. This attack represents an evolution of the Shai-Hulud threat, demonstrating the ongoing sophistication of software supply chain attacks targeting open-source repositories.
