AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

11:13 · June 9, 2026 · Hacker News AI Section

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and splintered to target specific ecosystems. "The compromised releases shipped a *-setup.pth file that attempts to execute automatically

Summary

A supply chain attack campaign tracked as Hades has placed malicious releases in 19 packages on the Python Package Index, resulting in 37 compromised wheel files. The packages deliver a *-setup.pth file that Python’s site module loads automatically at interpreter startup, allowing the payload to execute without any import by the consuming application. Once active, the code downloads the Bun JavaScript runtime from GitHub, then runs an obfuscated JavaScript stealer named _index.js that harvests credentials and configuration files for GitHub, npm, PyPI, cloud providers, CI/CD services, and local development tools.

The campaign is viewed as a PyPI-specific branch of the earlier Shai-Hulud and Miasma operations rather than an isolated Python incident. Attackers continue to rely on the same core sequence—abusing trusted package channels, staging a Bun-powered JavaScript payload, and exfiltrating data through GitHub repositories—while introducing incremental changes in persistence and evasion. In one cluster of bioinformatics-related packages the entry point is instead placed inside __init__.py as an obfuscated import hook, yet the outcome remains identical: Bun is fetched and the credential stealer is launched.

Additional refinements include a locale check that skips systems set to Russian, memory-scraping routines tailored for macOS and Windows GitHub Actions runners, and plain-text prompt injections intended to mislead LLM-based package scanners. The malware also polls GitHub commits for specific keywords to retrieve further payloads. These tactics illustrate how the same underlying playbook is being adapted across language ecosystems while exploiting the moment between package installation and first code review.

Why it matters

Python is the foundational programming language for AI development. Security professionals in the Dutch AI market must be aware of PyPI supply chain attacks to secure their AI development environments, protect proprietary models, and prevent credential theft.

More in this beat
githubHadesopen-source-securityPyPIsecurity-operationsshai-huludthreat-and-vulnerability-updates
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

20:37 · July 22, 2026

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

This article is highly relevant for security professionals as it highlights how AI is fundamentally altering the economics and operations of vulnerability management and bug bounties. Dutch enterprises running bug bounty programs or utilizing AI for code security must adapt to these shifts to effectively manage AI-generated reports and leverage new AI security models.

Relevance 75 · Audience 90

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

20:23 · July 20, 2026

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Directly addresses AI-specific security risks and privacy threats via malware in AI tooling ecosystems, with actionable recommendations applicable to Dutch teams using GitHub, MCP servers, or agentic AI. Aligns with EU data protection needs due to data-stealing payloads.

Relevance 85 · Audience 90

OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws

05:56 · June 23, 2026

OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws

This article is highly relevant for security professionals as it introduces a specialized AI tool for vulnerability detection and remediation. Dutch enterprises can leverage such models to strengthen their cybersecurity posture and comply with stringent EU security regulations like NIS2.

Relevance 85 · Audience 95

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

15:20 · June 11, 2026

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

The article highlights emerging security vulnerabilities specific to AI, such as the phishing of AI agents and patches for AI coding assistants like Claude. Dutch security professionals must understand these attack vectors to secure enterprise AI deployments and maintain compliance with strict EU data protection regulations.

Relevance 75 · Audience 85

⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More

15:18 · June 8, 2026

⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More

The mention of compromised AI helpers and fooled chatbots provides practical threat intelligence for security professionals. Dutch enterprises deploying AI solutions must be aware of these active vulnerabilities to secure their own implementations against prompt injection and token leaks.

Relevance 65 · Audience 80

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

19:23 · August 20, 2026

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

The article provides crucial updates on privacy-enhancing technologies for AI that are vital for GDPR compliance in the Netherlands. It also alerts security professionals to emerging AI-driven threats, such as uncensored LLMs and AI models capable of autonomous vulnerability exploitation, which require immediate defensive consideration.

Relevance 85 · Audience 95

AI Cybersecurity Needs Collective Defense, But Multiplying Alliances Risk Confusing Enterprise Buyers

17:48 · August 6, 2026

AI Cybersecurity Needs Collective Defense, But Multiplying Alliances Risk Confusing Enterprise Buyers

This article is highly relevant for Dutch security and privacy professionals as they navigate the complex landscape of global AI security frameworks and alliances. Understanding how to effectively integrate these collective defense initiatives is crucial for maintaining cyber resilience and compliance within the Dutch and broader EU regulatory environment.

Relevance 75 · Audience 90

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

10:04 · July 28, 2026

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

This article is highly relevant for security professionals as it demonstrates the practical application of AI in offensive cybersecurity and vulnerability research. It highlights a specific Linux kernel vulnerability that Dutch enterprises must patch, while also signaling the evolving threat landscape where AI accelerates exploit development.

Relevance 75 · Audience 90