Executive Summary
In June 2026, a sophisticated supply chain attack targeted the Python Package Index (PyPI), compromising 37 wheels across 19 packages. The attackers, adopting a 'Hades' naming convention, deployed a variant of the Shai-Hulud worm, which is known for its self-propagating and information-stealing capabilities. This malware infects software components, utilizes the access to publish malicious versions, and harvests repository accounts of downstream users. The attack chain's cross-runtime design involved the installation of Bun—a JavaScript runtime—as a heavily obfuscated JavaScript stealer before executing the payload.
This incident underscores the persistent and evolving nature of software supply chain threats. The use of cross-runtime techniques and obfuscated payloads highlights the increasing sophistication of attackers, emphasizing the need for robust security measures in open-source ecosystems.
Why This Matters Now
The 'Hades' campaign's exploitation of PyPI packages demonstrates the ongoing evolution of supply chain attacks, posing significant risks to software development and deployment processes. Organizations must prioritize securing their software supply chains to prevent similar incidents.
Attack Path Analysis
The Hades campaign compromised PyPI packages to distribute the Shai-Hulud malware, leading to unauthorized access, privilege escalation, lateral movement, command and control establishment, data exfiltration, and significant impact on affected systems.
Kill Chain Progression
Initial Compromise
Description
Attackers compromised PyPI packages to distribute the Shai-Hulud malware, leading to unauthorized access.
MITRE ATT&CK® Techniques
Command and Scripting Interpreter: JavaScript
Credentials from Password Stores: Cloud Secrets Management Stores
Automated Collection
Create or Modify System Process: Systemd Service
File and Directory Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
PyPI supply chain attacks targeting Python packages directly threaten software development workflows, CI/CD pipelines, and developer credential security across organizations.
Information Technology/IT
Shai-Hulud malware compromises IT infrastructure through poisoned packages, stealing cloud credentials and secrets essential for enterprise technology operations and management.
Financial Services
Supply chain vulnerabilities expose financial institutions to credential theft and regulatory compliance failures under PCI DSS and data protection requirements.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance violations and patient data exposure risks from compromised development tools and cloud service credentials.
Sources
- 'Hades' Campaign Against PyPI Puts New Spin on Shai-Huludhttps://www.darkreading.com/application-security/hades-campaign-pypi-shai-huludVerified
- Mini Shai-Hulud Escalates: 169 npm Packages, Mistral AI, UiPath, and Now PyPI — The Self-Spreading Supply-Chain Wormhttps://lyrie.ai/research/research/2026-05-12-mini-shai-hulud-escalationVerified
- PyPI and Shai-Hulud: Staying Secure Amid Emerging Threatshttps://blog.pypi.org/posts/2025-11-26-pypi-and-shai-hulud/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the Hades campaign as it would likely limit the malware's ability to escalate privileges, move laterally, establish command channels, and exfiltrate data, thereby reducing the attack's overall impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent the initial compromise via infected packages, it would likely limit the malware's ability to exploit further vulnerabilities within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the malware's ability to escalate privileges by enforcing strict access controls and minimizing trust between workloads.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely constrain the malware's lateral movement by monitoring and controlling internal traffic flows.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely detect and limit unauthorized command and control communications by providing comprehensive monitoring across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit data exfiltration by controlling and monitoring outbound traffic.
While Aviatrix Zero Trust CNSF may not entirely prevent the initial compromise, its comprehensive security measures would likely reduce the overall impact by limiting the malware's ability to escalate privileges, move laterally, establish command channels, and exfiltrate data.
Impact at a Glance
Affected Business Functions
- Software Development
- Continuous Integration/Continuous Deployment (CI/CD)
- Cloud Infrastructure Management
Estimated downtime: 7 days
Estimated loss: $500,000
Developer credentials, including GitHub tokens, npm credentials, AWS keys, Vault tokens, and Kubernetes service accounts, were exfiltrated.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic.
- • Utilize Threat Detection & Anomaly Response to identify and respond to malicious activities.
- • Apply Inline IPS (Suricata) to detect and prevent known exploit patterns.
- • Deploy Cloud Native Security Fabric (CNSF) for real-time inspection and enforcement of security policies.



