Hades cluster is a malware activity cluster associated with software supply chain compromises targeting the Python ecosystem. It has been linked to the broader Shai-Hulud and Miasma malware lineage. The cluster has been observed compromising legitimate PyPI packages through maintainer account takeover and inserting malicious startup-hook code that executes automatically when Python initializes, including during local development workflows and CI/CD jobs. The intrusion chain abuses Python .pth file behavior to achieve execution without requiring an explicit import of the compromised package. The malware establishes its own execution environment, retrieves a JavaScript runtime, and launches an obfuscated secondary payload, demonstrating a cross-runtime technique that bridges Python package compromise with JavaScript-based post-install execution. Observed payload behavior includes harvesting cloud authentication material, private SSH keys, and package-registry tokens associated with major cloud platforms, Kubernetes environments, and developer ecosystems. A notable characteristic of the cluster is its use of legitimate online services for operational camouflage. It has generated decoy traffic to benign cloud-hosted services while exfiltrating stolen data through automated interactions with GitHub, including creation of public repositories used to store collected data. Reported targeting has included widely used bioinformatics and deep-learning packages, indicating an emphasis on developers, research environments, and machine-learning related workflows. The activity is best characterized as financially or operationally motivated credential theft and data exfiltration conducted through open-source package ecosystem compromise. No high-confidence attribution to a specific country is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.