The Hades campaign exploits manipulated PyPI packages with automatically executing setup files to steal Bun login credentials in the Python supply chain.
Simple attack techniques remain effective despite known countermeasures, while undetected intrusions over extended periods revealed gaps in anomaly detection.
Microsoft disabled 73 GitHub repositories following a compromise by the Miasma worm, responding to a direct supply-chain attack on its developer infrastructure.
The Miasma worm spreads across Microsoft repositories on GitHub, demonstrating critical vulnerability of centrally managed development ecosystems to self-replicating attack malware.