Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A threat actor operating as the ‘Hades campaign’, linked with medium confidence to the Miasma/Shai-Hulud supply chain attack lineage, poisoned 19 PyPI packages across 37 malicious wheel artifacts, deploying credential-stealing and destructive capabilities that target the full modern software development and CI/CD stack. Organizations using Python-based developer tooling, AI coding assistants, and cloud platforms (AWS, GCP, Azure) face credential theft, lateral movement via SSH key harvesting, and potential data destruction via an embedded wiper module. The business risk is severe: a single developer installing one affected package can expose cloud credentials, CI/CD secrets, and source code repositories, with the wiper capability adding irreversible data loss to an already high-impact compromise. **Note: Specific package names require validation from primary source before operational use.**

Author

Tech Jacks Solutions