TL;DR: A coordinated PyPI supply chain attack has compromised 26 packages and 37 malicious wheel files, used Python startup hooks to run cross-runtime malware, and harvested cloud tokens, Kubernetes secrets, GitHub credentials, and AI assistant data across 14 systems, according to Orca Security. The lesson is that package trust, startup execution, and secret exposure must be governed as one identity problem, not separate controls.
Editorial analysis by NHI Mgmt Group, based on content published by Orca Security: “Massive PyPI Supply Chain Attack Harvests Cloud Credentials via Python Startup Hooks”.
By the numbers:
- A coordinated supply chain attack targeting PyPI has compromised 26 packages and 37 malicious wheel files.
- The attack targeted 14 systems with credential theft and exfiltration activity.
Key questions
Q: What breaks when a compromised Python package can run code at interpreter startup?
A: Package trust breaks down because the code runs before a developer or pipeline explicitly imports anything.
Q: Why do supply chain attacks on Python packages turn into cloud credential theft so often?
A: Because developer and CI environments usually hold the exact tokens attackers want: cloud provider credentials, GitHub access, registry keys, and Kubernetes secrets.
Q: What are the signs that a package supply chain attack has reached credential theft stage?
A: Look for unusual startup hooks, unexpected outbound downloads, repository creation with attacker-like naming patterns, new persistence services, and unauthorised workflow or commit activity.
Practitioner guidance
- Audit package startup execution paths Identify any .pth, sitecustomize, or similar startup mechanisms that can run before application code and flag them as execution surfaces.
- Rotate exposed cloud and publishing credentials Prioritise GitHub tokens, PyPI and npm publishing credentials, cloud provider tokens, Kubernetes secrets, SSH keys, and registry credentials that were reachable from affected environments.
- Hunt for persistence artefacts in developer environments Search for gh-token-monitor, update-monitor, and the lock files and service entries associated with the campaign across developer workstations and CI runners.
Bottom line: The Hades Campaign shows that a PyPI compromise can become a cloud credential theft event as soon as startup code can reach token-bearing environments.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Package trust is now an identity control, not a software distribution preference. The campaign shows that installation-time code execution can convert a benign dependency into a credential collection platform before any application logic runs. That means package governance, publishing rights, and runtime trust are part of the same control plane. Practitioners should treat dependency intake as identity exposure management, not only as vulnerability triage.
A few things that frame the scale:
- The attack sends decoy traffic to Anthropic AI servers to confuse network-level analysis, according to LLMjacking: How Attackers Hijack AI Using Compromised NHIs.
- Our research also shows that the average estimated time to remediate a leaked secret is 27 days, which is long enough for stolen credentials to be reused in a live campaign.
A question worth separating out:
Q: What should teams do after a package supply chain compromise is detected?
A: Contain first, then rotate. Isolate the affected hosts, remove or pin the malicious versions, hunt for persistence artifacts, and rebuild systems where possible before credential rotation. That sequence matters because revoking secrets too early can trigger deterrence logic or simply push the attacker to another compromised environment.
👉 Read our full editorial: Hades campaign shows how PyPI supply chain attacks steal cloud credentials
Package trust is now an identity control, not a software distribution preference. The campaign shows that installation-time code execution can convert a benign dependency into a credential collection platform before any application logic runs. That means package governance, publishing rights, and runtime trust are part of the same control plane. Practitioners should treat dependency intake as identity exposure management, not only as vulnerability triage.
A few things that frame the scale:
- The attack sends decoy traffic to Anthropic AI servers to confuse network-level analysis, according to LLMjacking: How Attackers Hijack AI Using Compromised NHIs.
- Our research also shows that the average estimated time to remediate a leaked secret is 27 days, which is long enough for stolen credentials to be reused in a live campaign.
A question worth separating out:
Q: What should teams do after a package supply chain compromise is detected?
A: Contain first, then rotate. Isolate the affected hosts, remove or pin the malicious versions, hunt for persistence artifacts, and rebuild systems where possible before credential rotation. That sequence matters because revoking secrets too early can trigger deterrence logic or simply push the attacker to another compromised environment.
👉 Read our full editorial: Hades campaign shows how PyPI supply chain attacks steal cloud credentials
Package trust is no longer separable from identity trust: when a dependency can execute at interpreter startup, the package manager becomes an access path into cloud credentials. That means PyPI compromise is not just a software supply chain event, it is a route to non-human identity theft across developer and CI environments. Practitioners need to treat package admission, runtime execution, and secret exposure as one governance domain.
A few things that frame the scale:
- 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should teams respond when package-based malware can touch developer and CI secrets?
A: Contain the affected environment first, then revoke the tokens and publishing credentials that were reachable from it. After that, rebuild the systems that executed the malware and inspect repositories for unauthorised changes. The key point is that response must address both code integrity and NHI compromise, not one or the other.
👉 Read our full editorial: Hades campaign shows how PyPI supply chain attacks steal cloud credentials