SlowMist identifies new Shai-Hulud Hades variant targeting PyPI

The malicious package uses a Python startup hook and obfuscated JavaScript to steal developer and cloud credentials, while sharing infrastructure with earlier Shai-Hulud attacks.

Summary

verifying reliability

Terms & Concepts

No specialized terms available for this topic.