The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent
On June 8, 2026, multiple Graph ML PyPI packages were compromised in the Hades campaign, deploying cross-platform memory scrapers, AI prompt injections for analyst misdirection, and token-revocation wipers. The attack targeted the bioinformatics ecosystem with sophisticated evasion techniques.
- Disclosed
- Last updated
- Blast radius
- Multiple Graph ML packages in the bioinformatics ecosystem; cross-platform impact via memory scrapers
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- Graph ML PyPI packagesMultiple packages in the bioinformatics ecosystem compromised in the Hades campaign
On June 8, 2026, multiple Graph ML PyPI packages were compromised as part of the Hades campaign. The compromised packages deployed malicious payloads across multiple platforms.
The attack employed several sophisticated techniques: cross-platform memory scrapers to extract sensitive data, AI prompt injections designed to misdirect security analysts and automated scanners, and a token-revocation wiper mechanism. These capabilities suggest a coordinated, well-resourced threat actor targeting the bioinformatics software supply chain.
The use of AI-based misdirection techniques indicates an attempt to evade both human and automated security analysis. The token-revocation wiper component suggests the attackers sought to cover their tracks and complicate incident response efforts.
Indicators of compromise
- Packages
- Graph ML PyPI packages
Remediation
- Immediately audit and revoke any tokens or credentials that may have been exposed through affected Graph ML packages
- Scan systems for memory scraper artifacts and indicators of compromise
- Review and update all dependencies on Graph ML PyPI packages to patched versions
- Implement enhanced monitoring for suspicious memory access patterns and token usage
- Conduct forensic analysis to identify the scope of data exfiltration
- Apply principle of least privilege to limit impact of future package compromises
Sources
Cite this entry
"The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 8, 2026; last updated June 8, 2026. https://supplychainattack.org/incident/the-hades-campaign-graph-ml-pypi-packages-deploy-cross-platform-memory-scrapers-1i5lk3
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in afrit-name (PyPI)
Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m7 (PyPI)
Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in xolonavrylpbeb (PyPI)
Malicious code was discovered in the xolonavrylpbeb package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41797.
PyPICompromised package - resolvedcritical
Malicious code in adrandom (PyPI)
The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package