JUST IN: SlowMist flags Shai-Hulud Hades, a PyPI-tied variant that auto-runs a .pth file, checks Bun, and deploys a multi-layer JS payload to steal credentials from GitHub, npm, AWS and other cloud services. This elevates credential‑teardown risk across dev ecosystems.

post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned