Hades Supply-Chain Campaign Plants Backdoors in AI Coding Assistant Configurations

· Original article ↗

Summary

Morphisec describes TeamPCP/UNC6780’s Hades supply-chain campaign, which uses Python startup hooks and malicious instructions in AI coding-tool configurations to run payloads, persist beyond package removal, and steal developer credentials.

Key points

  • The article attributes the campaign to TeamPCP, tracked by Google as UNC6780, and says it has operated since at least March 2026 through compromised open-source packages.
  • The article says the campaign stole 294,842 secrets from 6,943 developer machines by June and exfiltrated about 3,800 internal GitHub repositories.
  • Hades uses a Python .pth startup hook to run code when the interpreter starts, then uses the Bun JavaScript runtime to execute its payload.
  • The malware targets configuration files for 14 AI coding tools, injecting instructions and a startup hook that can execute with the developer’s permissions and remain after the malicious package is removed.
  • Hades includes comments intended to prompt AI code reviewers to approve the malicious package and produce a clean report.
  • The campaign published its attack pattern with a $1,000 bounty for the largest run; the article says copycat variants are already circulating.

Article Details

Attack Vectors
  • The source reports supply-chain compromise through hijacked trusted security tools and packages, followed by theft of developer credentials.
  • Hades uses a Python .pth startup hook to run when the interpreter starts, then pulls in Bun to execute its payload, avoiding monitoring focused on Node.
  • Hades places instructions in a comment at the top of a malicious file telling AI security reviewers to ignore the code and issue a clean report. The source reports that reviewers comply.
  • Hades modifies configuration files for 14 AI coding tools, injecting instructions and startup hooks that execute attacker code with permissions already granted to the assistant. The source reports that these modifications persist after removal of the malicious package.
  • The source reports a self-spreading worm and public release of its attack pattern, accompanied by a $1,000 prize for the largest attack run.
Defensive Notes
  • Package removal alone does not address the AI-assistant configuration persistence described in the article.
  • The described execution chain crosses Python and Bun; monitoring focused only on Node may miss it.
  • The article identifies attacker-authored code comments as a means of manipulating AI security review, making an AI-generated clean report unreliable in this scenario.
  • Morphisec advocates prevention before execution and claims its runtime memory protection blocks the payload regardless of its installation location. These are vendor claims; the article does not provide independent validation.
  • Morphisec presents continuous identification and prioritization of credential exposure as a complementary defense against stolen-secret abuse.

MITRE ATT&CK

People

Threat Actors

Malware

Vendors

Products

Adaptive Exposure ManagementMorphisec also provides Adaptive Exposure Management to continuously surface and prioritize credential exposure risk before attackers can act on it — closing the 94-day remediation window that makes stolen secrets soAutomated Moving Target Defense (AMTD)Morphisec’s Automated Moving Target Defense (AMTD) operates at the runtime memory layer — the layer where Hades’ payload ultimately has to execute regardless of how it arrived.BunWhen triggered, it silently pulls in Bun (a separate JavaScript runtime) to execute its payload.Claude CodeJune (Wave 1) Claude Code backdoor Red Hat npm packages backdoor Claude Code and VS CodeCodexHades hunts the configuration files of 14 AI coding tools — Claude Code, Cursor, GitHub Copilot, Google Gemini, Codex, and others — and injects its own instructions and a startup hook.CursorHades hunts the configuration files of 14 AI coding tools — Claude Code, Cursor, GitHub Copilot, Google Gemini, Codex, and others — and injects its own instructions and a startup hook.GitHubthe access, open-sourced its own attack toolkit with a $1,000 bounty for the biggest run, and breached GitHub’s internal repositories.GitHub CopilotHades hunts the configuration files of 14 AI coding tools — Claude Code, Cursor, GitHub Copilot, Google Gemini, Codex, and others — and injects its own instructions and a startup hook.Google GeminiHades hunts the configuration files of 14 AI coding tools — Claude Code, Cursor, GitHub Copilot, Google Gemini, Codex, and others — and injects its own instructions and a startup hook.LiteLLMMarch 2026 Wave 1 Hijacked trusted security tools: Trivy, Checkmarx, LiteLLM packagesPythonJune (Wave 2) Hades Python startup hooks + AI scanner manipulation + AI tool poisoningVS CodeJune (Wave 1) Claude Code backdoor Red Hat npm packages backdoor Claude Code and VS Code

Tools

Related Articles