Miasma PyPI Campaign Uses Malicious Wheels to Target Developer Credentials

· Original article ↗

Summary

Socket reports 37 malicious PyPI wheel artifacts across 19 packages that use executable .pth files to launch a Bun-powered JavaScript stealer targeting developer and CI/CD credentials.

Key points

  • The campaign involves 37 compromised wheel artifacts across 19 PyPI packages, apparently published through a maintainer-account takeover.
  • Executable .pth lines can run during Python startup, letting the loader execute without the affected package being imported; it attempts to download Bun and launch _index.js.
  • The obfuscated payload targets source-control, package-publishing, cloud, CI/CD, Kubernetes, Vault, SSH, and developer-tool credentials.
  • The payload uses GitHub repositories and Actions artifacts for exfiltration; the Anthropic API endpoint appears to be camouflage, with no indication Anthropic systems were compromised.
  • Socket links the activity to the Mini Shai-Hulud/Miasma lineage and identifies Hades-themed markers and persistence artifacts.
  • PyPI had quarantined some affected releases, while Socket reported remaining ones to PyPI; organizations that installed affected versions should rebuild where possible, remove or pin away from them, rotate accessible credentials, and search for listed indicators.

Article Details

Attack Vectors
  • Socket identified 37 malicious PyPI wheels across 19 packages. Simultaneous patch releases across one maintainer's portfolio appeared consistent with a maintainer-account takeover, but that explanation was not confirmed.
  • Compromised wheels contain executable *-setup.pth startup hooks intended to download Bun v1.3.13 and run the adjacent obfuscated _index.js credential stealer without requiring the victim to import the package.
  • The JavaScript payload targets developer-machine and CI/CD credentials, including package-publishing tokens, cloud secrets, SSH keys, configuration files, shell histories, and GitHub Actions secrets.
  • Recovered exfiltration logic creates public GitHub repositories containing encrypted/compressed results and uploads GitHub Actions secrets as workflow artifacts.
  • Recovered persistence and follow-on artifacts include user systemd service and LaunchAgent paths, a token-monitor script, Claude-related setup files, and GitHub workflow files.
Defensive Notes
  • Validate exploitability separately for each artifact. Socket's local CPython reproduction did not automatically resolve the adjacent _index.js because __file__ could resolve to site.py; the artifacts still contain a credential stealer and an attempted startup loader.
  • Remove or pin away from affected releases, rebuild affected environments where possible, and rotate credentials accessible to affected developer machines and CI jobs.
  • Affected releases are bramin 0.0.2, 0.0.3, 0.0.4; cmd2func 0.2.2, 0.2.3; coolbox 0.4.1, 0.4.2; dynamo-release 1.5.4; executor-engine 0.3.4, 0.3.5; executor-http 0.1.3, 0.1.4; funcdesc 0.2.2, 0.2.3; magique 0.6.8, 0.6.9; magique-ai 0.4.4, 0.4.5; mrbios 0.1.1, 0.1.2; napari-ufish 0.0.2, 0.0.3; nucbox 0.1.2, 0.1.3; okite 0.0.7, 0.0.8; pantheon-agents 0.6.1, 0.6.2; pantheon-toolsets 0.5.5, 0.5.6; spateo-release 1.1.2; synago 0.1.1, 0.1.2; ufish 0.1.2, 0.1.3; uprobe 0.1.3, 0.1.4.
  • Prioritize rotation of source-control and package-publishing tokens, cloud and Vault credentials, SSH keys, Docker credentials, cloud CLI profiles, and developer-tool tokens.
  • Detect executable .pth lines combined with network retrieval, temporary-directory executable installation, subprocess execution, and a staged JavaScript payload. Avoid rules dependent only on a specific runtime version or filename.
  • Monitor Python spawning Bun, temporary-directory Bun installation, and Bun executing _index.js. Inspect site-packages for *-setup.pth and _index.js.
  • Search GitHub organizations and CI workers for repositories described as Hades - The End for the Damned, the commit marker IfYouYankThisTokenItWillNukeTheComputerOfTheOwnerFully, results/results-*.json, format-results artifacts, suspicious Run Copilot workflows, and unexpected .github/workflows/codeql.yml changes.
  • The configured Anthropic API route returned 404 responses and could not deliver data to the attacker. Socket assessed it as network-log camouflage and reported no indication that Anthropic systems were compromised.

Indicators of compromise

TypeIndicatorContext
SHA256c539766062555d47716f8432e73adbe3a0c0c954a0b6c4005017a668975e275cMalicious *-setup.pth startup loader, identical across all affected artifacts.
SHA256dc48b09b2a5954f7ff79ab8a2fd80202bd3b59c08c7cdbc6025aa923cb4c0efeMalicious _index.js variant 1, reported as 4.8 MB and present in 17 packages.
SHA256e1342a80d4b5e83d2c7c22e1e0aaa95f2d88e3dbf0d853a4994b180c93a4b17dMalicious _index.js variant 2, reported as 4.7 MB and present in two packages.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationThe stealer uses character-code arrays, ROT-style substitution, rotated string tables, custom decoders, AES-GCM encryption, and gzip-protected strings.T1059.006 · PythonExecutable Python lines in *-setup.pth attempt to bootstrap Bun and launch the credential stealer during interpreter startup.T1059.007 · JavaScriptThe loader invokes Bun to execute _index.js; a decrypted JavaScript stage also launches the main payload with Bun.T1105 · Ingress Tool TransferThe startup loader downloads the Bun runtime from GitHub when no cached binary exists.T1140 · Deobfuscate/Decode Files or InformationJavaScript stages decode the outer wrapper and decrypt embedded AES-GCM blobs before writing and executing the main payload.T1195.001 · Compromise Software Dependencies and Development ToolsCompromised PyPI dependency releases distributed malicious wheels through trusted package channels.T1528 · Steal Application Access TokenThe stealer targets GitHub ghs_* tokens, package-publishing tokens, Kubernetes service-account tokens, and other service credentials.T1543.001 · Launch AgentRecovered persistence indicators include ~/Library/LaunchAgents/com.github.token-monitor.plist; deployment on victims was not established.T1543.002 · Systemd ServiceRecovered persistence indicators include ~/.config/systemd/user/gh-token-monitor.service; deployment on victims was not established.T1552.001 · Credentials In FilesThe recovered payload targets .env, .npmrc, .pypirc, Git credentials, Docker configurations, cloud CLI caches, and Claude/MCP configurations.T1552.003 · Shell HistoryThe credential stealer targets shell histories for developer-machine secrets.T1552.004 · Private KeysSSH keys are among the credential material targeted by the recovered payload.T1555.006 · Cloud Secrets Management StoresThe recovered payload targets AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Vault secrets.T1567.001 · Exfiltration to Code RepositoryThe payload can create public GitHub repositories and commit encrypted/compressed stolen-result envelopes under results/results-<timestamp>-<counter>.json.T1614.001 · System Language DiscoveryThe payload checks for Russian locale signals before proceeding.

People

Malware

Products

braminbramin@0.0.2Bunshipped a *-setup.pth file that attempts to execute automatically during Python startup, download the Bun JavaScript runtime, and run an obfuscated JavaScript payload named _index.js.cmd2funccmd2func@0.2.2coolboxRNA-velocity and expression-dynamics framework) and its spatial-transcriptomics sibling spateo-release, coolbox (GangCaoLab's Jupyter-based multi-omics genomic visualization toolkit for Hi-C/ChIP-Seq/RNA-Seq tracks),CPythonDefenders should validate exploitability per artifact. In standard CPython, executable .pth lines are executed by the site module, and __file__ can resolve to site.py rather than to the .pth file. In a local CPythondynamo-releasewhole portfolio at once. The risk concentrates in a handful of established bioinformatics tools: dynamo-release (the aristoteleo/dynamo single-cell RNA-velocity and expression-dynamics framework) and itsexecutor-engineexecutor-engine@0.3.4executor-httpexecutor-http@0.1.3funcdescfuncdesc@0.2.2GitHubhigh-value developer and CI/CD secret classes seen across Mini Shai-Hulud and Miasma waves, including GitHub, npm, PyPI, RubyGems, JFrog, CircleCI, Anthropic, AWS, GCP, Azure, Kubernetes, Vault, SSH keys, DockerGitHub ActionsGitHub credentials, GitHub Actions runner secrets, runner memory, and ghs_* tokens.magiquemagique@0.6.8magique-aimagique-ai@0.4.4mrbiosmrbios@0.1.1napari-ufishtoolkit for Hi-C/ChIP-Seq/RNA-Seq tracks), and the deep-learning FISH spot-detection tools ufish/napari-ufish. These are real and widely used research-community tools with cumulative download totals in thenpmthey download and install Bun, then use it as the execution engine. That behavior has shown up even in npm compromises, where Node.js would otherwise be the expected runtime.nucboxnucbox@0.1.2okiteokite@0.0.7pantheon-agentspantheon-agents@0.6.1pantheon-toolsetspantheon-toolsets@0.5.5PyPISocket detected a coordinated PyPI compromise involving 37 malicious wheel artifacts across 19 packages. The compromised releases shipped a *-setup.pth file that attempts to execute automatically during Python startup,PythonThe compromised releases shipped a *-setup.pth file that attempts to execute automatically during Python startup, download the Bun JavaScript runtime, and run an obfuscated JavaScript payload named _index.js.spateo-releasesingle-cell RNA-velocity and expression-dynamics framework) and its spatial-transcriptomics sibling spateo-release, coolbox (GangCaoLab's Jupyter-based multi-omics genomic visualization toolkit forsynagosynago@0.1.1ufishvisualization toolkit for Hi-C/ChIP-Seq/RNA-Seq tracks), and the deep-learning FISH spot-detection tools ufish/napari-ufish. These are real and widely used research-community tools with cumulative download totals inuprobeuprobe@0.1.3

Industries

Related Articles