forked from pypa/advisory-database
-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathPYSEC-0000-mrbios.yaml
More file actions
29 lines (29 loc) · 1.15 KB
/
Copy pathPYSEC-0000-mrbios.yaml
File metadata and controls
29 lines (29 loc) · 1.15 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
id: PYSEC-0000-mrbios.yaml
modified: 2026-06-30T21:23:05Z
published: 2026-06-30T21:23:05Z
summary: Malicious code in mrbios (PyPI)
aliases:
- MAL-2026-5282
details: |
Part of the "Hades" wave of the Shai-Hulud supply-chain campaign. On 2026-06-08,
malicious phantom releases of mrbios were published to PyPI using stolen
credentials. The package executes a bundled JavaScript payload (via the Bun
runtime) on import that harvests and exfiltrates credentials and attempts
self-propagation. This entry is a summary; behavior may not be fully
characterized here. See the linked references for detailed analysis and
indicators of compromise.
affected:
- package:
name: mrbios
ecosystem: PyPI
purl: pkg:pypi/mrbios
versions:
- 0.1.1
- 0.1.2
references:
- type: EVIDENCE
url: https://inspector.pypi.io/project/mrbios/0.1.2/packages/57/fb/c33c8829af52faa727d93f68688a53322e10e5f617c6b26f86f9c9ad35b9/mrbios-0.1.2-py3-none-any.whl//mrbios-setup.pth
- type: ARTICLE
url: https://www.endorlabs.com/learn/shai-hulud-hades-wave-hits-six-pypi-bioinformatics-packages
- type: ARTICLE
url: https://www.stepsecurity.io/blog/the-hades-campaign-pypi-pack