The Miasma and Hades worms are actively spreading across npm and PyPI ecosystems, executing malicious code not at install time but when developers open projects or import packages. Miasma uses a 'Phantom Gyp' technique via a malicious binding.gyp file, while Hades embeds an obfuscated hook in __init__.py that downloads a Bun runtime on import. Both worms steal publishing tokens and self-replicate by infecting every package the stolen token can publish. Traditional defenses — EDR, registry gateways, SCA scanners — all miss these attacks because they target install-time, not open/import-time execution. StepSecurity's Dev Machine Guard now includes a Suspicious Files feature that detects the artifacts these worms drop on developer machines, with centrally managed detection rules that update automatically as the campaign evolves.

8m read timeFrom stepsecurity.io
Post cover image
Table of contents
Why this is urgentHow the attack evolved: from install to importWhy current defenses miss thisWhat Suspicious Files detectsManaged detection, nothing to configureWhy this mattersHow to get started
232 Impressions