Hades is a malware name used in two distinct contexts in the provided content. Most extensively, it refers to a 2026 supply-chain malware family/variant within the Mini Shai-Hulud / Miasma lineage targeting developer ecosystems, especially PyPI and also related npm/Go compromises. In that context, Hades was observed in malicious PyPI waves affecting 37 wheel artifacts across 19 packages, with later reporting on 23 additional malicious PyPI package versions. Delivery mechanisms included Python *-setup.pth startup hooks that execute on interpreter startup, compiled .abi3/.abi.so native-extension triggers on import, obfuscated init.py hooks, and at least one split-delivery loader package. The malware downloads the Bun JavaScript runtime and executes an obfuscated _index.js stealer payload. Reported tradecraft includes multi-layer obfuscation, AES-GCM encryption, PBKDF2 key derivation, GitHub dead-drop tasking, hourly polling for GitHub commits containing markers such as "firedalazer" and "TheBeautifulSnadsOfTime," and prompt-injection blocks intended to mislead naive LLM-based analysis tools. High-confidence capabilities described in the content include theft of GitHub, npm, PyPI, RubyGems, JFrog, CircleCI, Anthropic/Claude, AWS, Azure, GCP, Kubernetes, Vault, Docker, SSH, shell-history, .env, and AI-assistant configuration secrets from developer workstations and CI/CD environments; exfiltration via GitHub repositories created or accessed with stolen victim tokens; GitHub Actions secret theft including a fake "Run Copilot" workflow; persistence via .pth files, gh-token-monitor, Linux systemd user services, and macOS LaunchAgents; IDE/AI-assistant backdooring; lateral movement via SSH/SCP; and worm-like propagation by using stolen credentials to publish trojanized packages or modify repositories and workflows. The content ties this Hades lineage to bioinformatics, AI/MCP-themed, cloud-native, and serverless developer targets, including Leo/RStreams-related packages and multiple bioinformatics utilities. Separately, the content also references Hades ransomware, a ransomware family associated with Evil Corp / Indrik Spider and used in some UNC2165 activity, reportedly developed or adopted after WastedLocker to help evade OFAC sanctions. Because the supplied content mixes these two malware usages under the same name, attribution and behavior should be interpreted carefully by context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware has been previously linked to Evil Corp, a Russian cybercrime gang active since 2007 that has been associated with the Zeus and Dridex malware families and was behind the WastedLocker, Hades, Macaw Locker, and Phoenix CryptoLocker ransomware operations.
A recently discovered variant of the Mini Shai-Hulud supply chain malware, dubbed “Hades,” was discovered in 23 new PyPI package versions targeting bioinformatics and AI-themed packages... The variant is named for the Hades and Greek mythology-themed markers present in the GitHub repositories the malware uses for exfiltration of stolen data.
Once executed via any of the three delivery branches, the Hades-family payload aggressively harvests secrets from developer workstations and CI/CD environments.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Предположительно, хакеры использовали утекшие учетные данные и сумели получить токен npm.
~/.config/systemd/user/gh-token-monitor.service ~/Library/LaunchAgents/com.user.gh-token-monitor.plist ~/.local/share/updater/update.py ~/.local/share/updater/ update-monitor.service
When npm sees a package with binding.gyp and no explicit install script, it falls back to running node-gyp rebuild. During that process, node-gyp expands shell commands embedded in <!(...) expressions. Attackers can abuse this behavior to execute the payload during package installation... "sources" : [ "<!(node index.js > /dev/null 2>&1 && echo stub.c)" ]
~/.config/systemd/user/gh-token-monitor.service ~/Library/LaunchAgents/com.user.gh-token-monitor.plist ~/.local/share/updater/update.py ~/.local/share/updater/ update-monitor.service
Предположительно, хакеры использовали утекшие учетные данные и сумели получить токен npm.
~/.config/systemd/user/gh-token-monitor.service ~/Library/LaunchAgents/com.user.gh-token-monitor.plist ~/.local/share/updater/update.py ~/.local/share/updater/ update-monitor.service
Defense Evasion Obfuscated/Encrypted Files & Information T1027 ROT‑17 → AES‑128‑GCM → obfuscator.io → custom G1 cipher (4 layers)
Credential Access Steal Application Access Token T1528 GitHub/npm/PyPI/RubyGems/Azure/GCP/Anthropic tokens & OIDC exchange
Credential Access Credentials in Files T1552.001 ~/.aws , ~/.npmrc , ~/.pypirc , Vault token files, wallets
It retains the familiar behavior: Broad credential collection from files, environment variables, shell history, GitHub CLI tokens, cloud credentials, package-manager tokens, and CI/CD environments.
It retains the familiar behavior: Broad credential collection from files, environment variables, shell history, GitHub CLI tokens, cloud credentials, package-manager tokens, and CI/CD environments.
abusing legitimate platforms like GitHub and Hugging Face as C2 servers, and uploading stolen credentials directly into GitHub repositories, blending malicious traffic with the noise of normal developer activity.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
You may like AI coding agents can be tricked into installing malware via 'clean' GitHub repositories ... Hades malware campaign tricks AI scanners with fake nuclear weapon prompts
Named as one of the malware families observed in the new attack wave, but not further described in the article.
Referenced only as part of a related article title; no substantive details are provided in the content.
A variant in the same malware lineage that is retrieved from GitHub dead-drop style infrastructure and executed as part of the broader credential-stealing supply-chain campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.