{
  "Event": {
    "analysis": "1",
    "date": "2026-06-07",
    "extends_uuid": "",
    "info": "[Threat Intel] Miasma Worm Campaign Spreads with New PyPI Wave",
    "protected": false,
    "publish_timestamp": "1781219603",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1781219603",
    "uuid": "2fc4fdf6-de9a-429f-b64f-32c47d775473",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:producer=\"37ebf9d7-5e9a-466f-a42c-6e60313db868\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"Shai-Hulud\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#18005e",
        "local": false,
        "name": "rectifyq:topic=\"supply-chain\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#230087",
        "local": false,
        "name": "rectifyq:samples-found-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780916406",
        "to_ids": false,
        "type": "link",
        "uuid": "f7989149-1728-49bd-8bc7-2cae5f984cfe",
        "value": "https://socket.dev/blog/shai-hulud-descends-to-hades-miasma-pypi-wave"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780916406",
        "to_ids": false,
        "type": "text",
        "uuid": "5d5383e4-6df3-47fb-a3cd-7848be938e3f",
        "value": "A coordinated PyPI compromise campaign involving 37 malicious wheel artifacts across 19 packages was detected, utilizing Python startup hooks to execute credential-stealing payloads. The attack leverages .pth files for automatic execution during Python interpreter startup, downloads the Bun JavaScript runtime, and runs obfuscated JavaScript payloads. The malware targets high-value developer and CI/CD credentials including GitHub, npm, PyPI, cloud providers (AWS, GCP, Azure), Kubernetes, Vault, SSH keys, and AI tool tokens. This represents a PyPI branch of the Shai-Hulud/Miasma campaign family, using a Hades-themed variant for GitHub exfiltration. Compromised packages included established bioinformatics tools with significant download counts, stemming from apparent maintainer account takeover. The payload employs multi-layer obfuscation, AES-GCM encryption, and exfiltrates data through GitHub repositories with distinctive markers. The campaign demonstrates cross-runtime attack capabilities and ecosystem-spe..."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780916406",
        "to_ids": false,
        "type": "text",
        "uuid": "2f506ad6-88ff-4f92-95e6-cbb34c838843",
        "value": "Name: Miasma Worm Campaign Spreads with New PyPI Wave\nAuthor: AlienVault\nAdversary: Shai-Hulud\nTags: [\"pypi\", \"supply chain attack\", \"bun runtime\", \"github exfiltration\", \"hades\", \"miasma\", \"startup hooks\", \"mini shai-hulud\", \"credential theft\", \"bioinformatics\"]\nTgtd countries: []\nMlwr families: [\"Hades\", \"Miasma\", \"Mini Shai-Hulud\"]\nAttack_ids: []\nIndustries: [\"Technology\", \"Healthcare\"]"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780916406",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "07861216-92f0-4922-bb7b-b22db953c5a9",
        "value": "Shai-Hulud"
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1781218452",
        "uuid": "27bf7073-14a2-4ff0-b669-fceb4d02bdee",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1781218452",
            "to_ids": true,
            "type": "md5",
            "uuid": "a94cf287-2ab6-4747-9def-a4761fcbb090",
            "value": "ca160c601cfb9b468814d1f39cf3131e",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1781215102",
            "to_ids": true,
            "type": "sha1",
            "uuid": "9f1170a4-4018-42c7-9f4a-ad27f8b62192",
            "value": "5e1d933b28cd2fef441ef36a135a285ece528136",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1781215102",
            "to_ids": true,
            "type": "sha256",
            "uuid": "c1f72301-8484-437b-8b88-b63970466943",
            "value": "c539766062555d47716f8432e73adbe3a0c0c954a0b6c4005017a668975e275c",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1781214214",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "4a1609eb-3191-4ffb-b21f-89767b4b30e1",
            "value": "24:82f+BZlYktoeNiuQ/3XFpa/lJMBCGWCZwN:82etoJJ/3X3a9fx"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1781214214",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "482523bf-9733-4ccf-9158-5ab3bf32ba40",
            "value": "881"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1781214215",
            "to_ids": true,
            "type": "filename",
            "uuid": "ed4e0606-1e28-462e-913c-d7ae8586bd96",
            "value": "magique_ai-setup.pth"
          },
          {
            "category": "Other",
            "comment": "Checked: 12/06/2026\nLast-scan\t:  11/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1781214215",
            "to_ids": false,
            "type": "text",
            "uuid": "67cf8018-926d-4bb7-9611-229d714c0974",
            "value": "Type Description: Text\nMicrosoft: Trojan:JS/MiasmaWorm.DB!MTB\nVT Total Detection:20/62\nFirst Submission:2026-06-05T23:31:39.000000+00:00\nLast Submission:2026-06-05T23:31:39.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1781218473",
        "uuid": "fb45c436-99ce-4470-b990-04e835bd1505",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1781218473",
            "to_ids": true,
            "type": "md5",
            "uuid": "c92f5b63-ca86-4b68-a06a-141bd903ddca",
            "value": "ee73800e5890cca31a1ff7895d2a3374",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1781215103",
            "to_ids": true,
            "type": "sha1",
            "uuid": "55b74b19-70fb-4109-9584-51cbb02163c7",
            "value": "460f9bba9509e64a93274b2e42d1a21af9f482e0",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1781215103",
            "to_ids": true,
            "type": "sha256",
            "uuid": "d9454046-f9bc-49c4-99b5-30cece097734",
            "value": "dc48b09b2a5954f7ff79ab8a2fd80202bd3b59c08c7cdbc6025aa923cb4c0efe",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1781214236",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "10281bdb-b37b-4344-8247-5e2f913782cc",
            "value": "768:A19X4Uj7S2/Mji7iDHyBHnnR3dQEGN4n3GQtmZc2E5bVPjW/Gz17FpfzDjOqF2gI:A+"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1781214236",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "5ae876f5-f8dc-40f3-be95-349501327d7c",
            "value": "5015390"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1781214236",
            "to_ids": true,
            "type": "vhash",
            "uuid": "77214d43-db99-48c4-ac08-68289198f657",
            "value": "4b37ee64e39a6449904a4968eb4bf1ed"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1781214236",
            "to_ids": true,
            "type": "filename",
            "uuid": "dd4980f7-403f-43c0-a94a-75ea3269c104",
            "value": "_index.js"
          },
          {
            "category": "Other",
            "comment": "Checked: 12/06/2026\nLast-scan\t:  12/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1781214236",
            "to_ids": false,
            "type": "text",
            "uuid": "0c214d38-f726-48e3-b1ab-db845a161fef",
            "value": "Type Description: JavaScript\nMicrosoft: Trojan:JS/MiniShaiHrd.ZA!MTB\nVT Total Detection:29/61\nFirst Submission:2026-06-05T23:30:39.000000+00:00\nLast Submission:2026-06-07T17:59:50.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1781218495",
        "uuid": "0ae5df05-e417-4985-88d8-050ebf74be2b",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1781218495",
            "to_ids": true,
            "type": "md5",
            "uuid": "305334e3-f566-4d76-882d-43c96a8e3205",
            "value": "bb3ed98dd2bfdc4d739525387657c40d",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1781215104",
            "to_ids": true,
            "type": "sha1",
            "uuid": "5339acb5-af4a-443b-9f56-3e3aab4a3048",
            "value": "a32d571f187e764ff9222d4a61ebb57894597571",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1781215104",
            "to_ids": true,
            "type": "sha256",
            "uuid": "eed12bfd-f607-4241-98ad-42c0ef8af970",
            "value": "e1342a80d4b5e83d2c7c22e1e0aaa95f2d88e3dbf0d853a4994b180c93a4b17d",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1781214258",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "3768d591-ac7b-419e-a813-9fa96a217ecc",
            "value": "768:AJe/H/iAuIAP/9fFaQ3X6dTAtH3wg9fkvKEEynwhbetNGyLI+K+ypPFknlZyWqak:AZ"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1781214258",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "a516dca7-896f-4f11-9828-90eb30a5b496",
            "value": "4920723"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1781214258",
            "to_ids": true,
            "type": "vhash",
            "uuid": "f302dabf-ce30-4a1f-81cc-f241ef439685",
            "value": "4b37ee64e39a6449904a4968eb4bf1ed"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1781214258",
            "to_ids": true,
            "type": "filename",
            "uuid": "6b17a9bc-d6d2-4bf4-8d7f-cb3386474b90",
            "value": "_index.js"
          },
          {
            "category": "Other",
            "comment": "Checked: 12/06/2026\nLast-scan\t:  12/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1781214258",
            "to_ids": false,
            "type": "text",
            "uuid": "6abf38dd-411c-4f90-a7a7-7fd91d52d916",
            "value": "Type Description: JavaScript\nMicrosoft: Trojan:JS/MiniShaiHrd.ZA!MTB\nVT Total Detection:29/61\nFirst Submission:2026-06-06T00:16:25.000000+00:00\nLast Submission:2026-06-06T00:16:25.000000+00:00"
          }
        ]
      }
    ]
  }
}