Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A credential-stealing attack framework called Miasma was leaked publicly and weaponized into the ‘Hades Campaign,’ a multi-stage supply chain attack targeting open-source package registries (PyPI, npm, RubyGems), CI/CD pipelines, and developer environments. Over 304 software components and 73 Microsoft GitHub repositories are reported affected, with attackers injecting malicious code into widely used packages and stealing secrets including API keys, tokens, and credentials from pipeline configurations. Organizations that consume open-source packages or run automated build pipelines face immediate risk of software supply chain compromise, backdoored software delivery, and downstream credential theft at scale.

Author

Tech Jacks Solutions