Four Supply Chain Attacks Hit npm and PyPI Between June and July 2026

Between early June and July 14, 2026, four separate supply chain attacks targeted the npm and PyPI open-source package ecosystems. The Miasma worm, previously identified on npm, spawned a PyPI variant called Hades that spread across at least 29 packages by using a Python startup file to execute credential-harvesting payloads. A separate campaign deployed roughly 17 fake payment SDK packages mimicking providers like PaySafe and Skrill, silently stealing API keys and tokens from CI environments while returning normal-looking responses to developers. Attackers also used stolen publishing credentials to push malicious versions of the jscrambler package and several of its build-tool plugins, which collectively carry millions of weekly downloads. Across all four incidents, the common objective was to compromise developer environments and build pipelines in order to exfiltrate credentials.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in