Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
The Miasma and Hades worms are actively spreading across npm and PyPI ecosystems, executing malicious code not at install time but when developers open projects or import packages. Miasma uses a 'Phantom Gyp' technique via a malicious binding.gyp file, while Hades embeds an obfuscated hook in __init__.py that downloads a Bun runtime on import. Both worms steal publishing tokens and self-replicate by infecting every package the stolen token can publish. Traditional defenses — EDR, registry gateways, SCA scanners — all miss these attacks because they target install-time, not open/import-time execution. StepSecurity's Dev Machine Guard now includes a Suspicious Files feature that detects the artifacts these worms drop on developer machines, with centrally managed detection rules that update automatically as the campaign evolves.