GitGuardian
Read post

Four More Supply Chain Attacks Hit npm and PyPI

Between early June and July 14, 2026, four distinct supply chain attacks targeted npm and PyPI ecosystems. The Shai-Hulud/Miasma worm spread to PyPI via a Python startup file (.pth) mechanism, infecting over 100 packages total. Fake payment SDK packages (typosquatting PaySafe, Skrill, Neteller) harvested CI secrets like AWS keys and GitHub tokens. A stolen npm publishing token poisoned Jscrambler and its plugins with an IronWorm variant that targeted AI coding assistant credentials. Finally, a GitHub Actions 'pwn request' attack hijacked AsyncAPI's CI pipeline, backdooring packages with 2.25M+ weekly downloads — and the malicious releases carried valid Sigstore/SLSA provenance because the attacker controlled the CI identity. All four attacks shared one goal: stealing credentials from developer environments and build pipelines. npm v12 disabled install scripts by default, but attackers quickly pivoted to import-time execution, bypassing that protection.

    #security#python#malware#github-actions#npm
Jul 22•7m read time•From blog.gitguardian.com
Post cover image
Table of contents
Attack 1: Hades Brings the Shai-Hulud Worm to PyPIAttack 2: Fake Payment SDKs Harvest CI Secrets on npm and PyPIAttack 3: A Stolen npm Token Poisons JscramblerAttack 4: AsyncAPI's Own CI Pipeline Turned Against ItThe Common Thread
11.2K Impressions
GitGuardian's image
GitGuardian

GitGuardian Blog provides insights, tutorials, and updates on secrets management, code security, and...

96 Followers

•

969 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard