{
  "Event": {
    "analysis": "1",
    "date": "2026-06-08",
    "extends_uuid": "",
    "info": "[Threat Intel] Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels",
    "protected": false,
    "publish_timestamp": "1781329225",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1781329225",
    "uuid": "8eee07e7-887b-48a2-992b-ef62ef5ffaab",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#d3f567",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#7da4ad",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#47d9d3",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#68f2ff",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9bb6d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials from Password Stores - T1555\"",
        "relationship_type": ""
      },
      {
        "colour": "#bce57a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Web Service - T1567\"",
        "relationship_type": ""
      },
      {
        "colour": "#e7d11f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Private Keys - T1552.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#474886",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Dynamic Linker Hijacking - T1574.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#36a9d8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Account Discovery - T1087\"",
        "relationship_type": ""
      },
      {
        "colour": "#f95f85",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Group Policy Preferences - T1552.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#f5055a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#d596aa",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d37d8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Python - T1059.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#07a4a1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data Encoding - T1132\"",
        "relationship_type": ""
      },
      {
        "colour": "#a42e64",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Information Repositories - T1213\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:producer=\"37ebf9d7-5e9a-466f-a42c-6e60313db868\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"Shai-Hulud\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#18005e",
        "local": false,
        "name": "rectifyq:topic=\"supply-chain\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781002826",
        "to_ids": false,
        "type": "link",
        "uuid": "0e04ab1d-1dde-4379-910a-dfefc17b24ad",
        "value": "https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781002826",
        "to_ids": false,
        "type": "text",
        "uuid": "b3f2f5b9-6bec-4652-97bb-adee0408be66",
        "value": "A sophisticated supply chain attack campaign has expanded to 471 affected artifacts across npm and PyPI, targeting developers through malicious packages. The campaign uses three distinct delivery methods: executable .pth startup hooks, trojanized native .abi3.so extensions that execute at import time, and a split loader-payload architecture that searches Python's sys.path. Twenty-three newly identified PyPI packages masquerade as bioinformatics tools, AI frameworks, and popular libraries like requests and Flask. The attack deploys heavily obfuscated JavaScript stealers via Bun runtime, harvesting high-value credentials including GitHub tokens, npm registry access, cloud credentials, SSH keys, and CI/CD secrets. The malware employs anti-analysis techniques with fake LLM prompt-injection headers designed to disrupt AI-assisted security scanners, while targeting developer workstations and automated build environments."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781002826",
        "to_ids": false,
        "type": "text",
        "uuid": "e472ca0f-4cab-40f0-9e19-a6be4b51d29f",
        "value": "Name: Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels\nAuthor: AlienVault\nAdversary: \nTags: [\"mcp developers\", \"bun runtime\", \"miasma\", \"native extensions\", \"credential theft\", \"supply chain attack\", \"ci/cd compromise\", \"hades\", \"typosquatting\", \"bioinformatics\", \"mini shai-hulud\", \"javascript stealer\", \"pypi\"]\nTgtd countries: []\nMlwr families: [\"Hades\", \"Mini Shai-Hulud\", \"Miasma\"]\nAttack_ids: [\"T1059.007\", \"T1036.005\", \"T1204.002\", \"T1005\", \"T1140\", \"T1555\", \"T1567\", \"T1552.004\", \"T1574.006\", \"T1087\", \"T1552.001\", \"T1552.006\", \"T1039\", \"T1027\", \"T1195.002\", \"T1059.006\", \"T1132\", \"T1213\", \"T1071.001\"]\nIndustries: [\"Technology\"]"
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1781327924",
        "uuid": "a706da35-383d-4cf7-b024-4ab1014e9887",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1781327924",
            "to_ids": true,
            "type": "md5",
            "uuid": "25e62ae9-999d-4fb8-a06a-1b151d803b6c",
            "value": "850162a95fd18646bb391e25606f9b8f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1781323600",
            "to_ids": true,
            "type": "sha1",
            "uuid": "ba0a5598-ccac-4ca6-9b9b-7340124f3def",
            "value": "c2bc65df73f74b7a53ea1c67894af949a9b47d91",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1781323600",
            "to_ids": true,
            "type": "sha256",
            "uuid": "ebb30d59-7e05-49e6-815f-8c69485b6a9d",
            "value": "6506d31707a39949f89534bf9705bcf889f1ecae3dbc6f4ff88d67a8be3d01b2",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1781322147",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "a2bf61bf-ec44-45d9-9461-c7d9be389788",
            "value": "24:82f+BZlKAzyq2XGzNNEOud/qFkVEOzv0VMuWq3449+CYeN:82pAyXG3EOg/qfOz+MuWqN9+o"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1781322147",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "1d9e88c3-a6c1-46ae-98c8-9dd1c5854dbf",
            "value": "1315"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1781322147",
            "to_ids": true,
            "type": "filename",
            "uuid": "a7d832c9-30c5-4dfb-bee9-80cb6dab2ada",
            "value": "langchain_core-setup.pth"
          },
          {
            "category": "Other",
            "comment": "Checked: 13/06/2026\nLast-scan\t:  12/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1781322147",
            "to_ids": false,
            "type": "text",
            "uuid": "d96ccac9-629f-4d70-8428-a54e0c2f2731",
            "value": "Type Description: Text\nMicrosoft: Trojan:Python/ShaiHulud.LTSN!MTB\nVT Total Detection:22/62\nFirst Submission:2026-06-07T14:46:54.000000+00:00\nLast Submission:2026-06-09T10:34:49.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1781327945",
        "uuid": "95575dcd-161a-4461-8626-7b9eb54d81ae",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1781327945",
            "to_ids": true,
            "type": "md5",
            "uuid": "1bfa14f1-a58b-4c91-b391-484b8b6c9878",
            "value": "ad1b6e93c997d42b14a412a0fd7062b6",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1781323601",
            "to_ids": true,
            "type": "sha1",
            "uuid": "ca7ed9e0-ec7e-46f8-8d6f-c725cee118ca",
            "value": "848d99184525b07a1bd30708a637f60193157d4f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1781323601",
            "to_ids": true,
            "type": "sha256",
            "uuid": "c2ccd065-895c-4457-a583-cae7e3b1a4b2",
            "value": "6d332f814f15f19758d65026bbfd0a8c49671b319ec77b8fa1b27fc48afff7d9",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1781322170",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "57b5ff6d-6b87-4cf7-8c34-6b9271321abc",
            "value": "12288:7p9gqceBIjtMVdsT+Uew00yDKMnUZid2VbbjYWhfty/FiE+:7pZ7OjCdsTjp00aIiIVvJyK"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1781322170",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "521a5b86-2de6-4bb6-8cf5-4064e8dc074d",
            "value": "561435"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1781322170",
            "to_ids": true,
            "type": "vhash",
            "uuid": "613a182f-e57d-4de3-bcc7-7110afc572ce",
            "value": "c692519ffe90226e12983ae3db30cbe5"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1781322170",
            "to_ids": true,
            "type": "filename",
            "uuid": "21503979-0de2-4695-84ee-aa864a800622",
            "value": "langchain_core_mcp-1.4.2-py3-none-any.whl"
          },
          {
            "category": "Other",
            "comment": "Checked: 13/06/2026\nLast-scan\t:  13/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1781322170",
            "to_ids": false,
            "type": "text",
            "uuid": "0cc3e216-4751-4284-bf0c-e76468049abd",
            "value": "Type Description: ZIP\nMicrosoft: None\nVT Total Detection:24/66\nFirst Submission:2026-06-07T23:00:41.000000+00:00\nLast Submission:2026-06-07T23:00:43.000000+00:00"
          }
        ]
      }
    ]
  }
}