<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/meet-hades-the-malware-that-lies-to-ai-security-agents-vv9ypkqgb" -->

---
title: Meet Hades: The malware that lies to AI security agents
description: Researchers at StepSecurity have uncovered the Hades Campaign, a sophisticated supply-chain attack targeting Python developer environments. The malware hides...
canonical: https://daily.dev/posts/meet-hades-the-malware-that-lies-to-ai-security-agents-vv9ypkqgb
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Meet Hades: The malware that lies to AI security agents | daily.dev
og:description: Researchers at StepSecurity have uncovered the Hades Campaign, a sophisticated supply-chain attack targeting Python developer environments. The malware hides...
og:url: https://daily.dev/posts/meet-hades-the-malware-that-lies-to-ai-security-agents-vv9ypkqgb
og:image: https://api.daily.dev/og/posts/vV9yPkqgB.png
og:image:alt: Meet Hades: The malware that lies to AI security agents
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Meet Hades: The malware that lies to AI security agents

**[InfoWorld](https://daily.dev/sources/infoworld)** · 5 min read · 0 upvotes · 0 comments

## Summary

Researchers at StepSecurity have uncovered the Hades Campaign, a sophisticated supply-chain attack targeting Python developer environments. The malware hides inside Python package __init__.py files, drops a precompiled Bun runtime to execute JavaScript payloads, and propagates like a worm across networks. It harvests credentials, scrapes memory on Linux, macOS, and Windows, and exfiltrates data via public GitHub repositories. Most notably, it uses adversarial prompt injection to trick LLM-based code analysis tools into classifying malicious packages as safe. The campaign also exploits GitHub Actions OIDC tokens to publish cryptographically signed but compromised packages to PyPI and npm, and targets configuration files for 14 AI agents to plant persistent malicious instructions.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.infoworld.com/article/4182692/meet-hades-the-malware-that-lies-to-ai-security-agents.html>

## Similar posts on daily.dev

- [The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent](https://daily.dev/posts/the-hades-campaign-graph-ml-pypi-packages-deploy-cross-platform-memory-scrapers-ai-analyst-misdire-rhp4rxad7) · StepSecurity · 0 upvotes · 0 comments
- [Massive PyPI Supply Chain Attack Harvests Cloud Credentials via Python Startup Hooks](https://daily.dev/posts/massive-pypi-supply-chain-attack-harvests-cloud-credentials-via-python-startup-hooks-pbx2b1ksk) · Orca Security Blog · 0 upvotes · 0 comments
- [Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files](https://daily.dev/posts/miasma-and-hades-are-spreading-now-detect-them-on-developer-machines-with-suspicious-files-3mwveqhbm) · StepSecurity · 0 upvotes · 0 comments
- [Hermes AI agent used to automate attack on Thai Finance Ministry](https://daily.dev/posts/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry-p8yly5m4s) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#python](https://daily.dev/tags/python), [#malware](https://daily.dev/tags/malware), [#prompt-injection](https://daily.dev/tags/prompt-injection)

[View this post on daily.dev](https://daily.dev/posts/meet-hades-the-malware-that-lies-to-ai-security-agents-vv9ypkqgb)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Meet Hades: The malware that lies to AI security agents","url":"https://daily.dev/posts/meet-hades-the-malware-that-lies-to-ai-security-agents-vv9ypkqgb","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/meet-hades-the-malware-that-lies-to-ai-security-agents-vv9ypkqgb"},"datePublished":"2026-06-09T05:08:17.897Z","dateModified":"2026-06-09T05:08:44.620Z","description":"Researchers at StepSecurity have uncovered the Hades Campaign, a sophisticated supply-chain attack targeting Python developer environments. The malware hides...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/326aff20348653a3bcd7fae71a706cd3?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/326aff20348653a3bcd7fae71a706cd3?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"InfoWorld","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"InfoWorld","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/bf6d68a999064029b0bb09aa6268f1f3","url":"https://daily.dev/sources/infoworld"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/meet-hades-the-malware-that-lies-to-ai-security-agents-vv9ypkqgb","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,python,malware,prompt-injection","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"InfoWorld","item":"https://daily.dev/sources/infoworld"},{"@type":"ListItem","position":3,"name":"Meet Hades: The malware that lies to AI security agents"}]}
```

