—
title: “Hades: The Malware That Lies to AI Security Agents”
author: Victor Kane
date: 2026-06-06
category: AI
excerpt: A new supply chain campaign targets Python devs, uses Bun to run hidden JavaScript, and injects adversarial prompts to trick LLM-based security scanners into saying the code is clean.
—

Hades is not the most technically sophisticated malware discovered this year. It is the most strategically interesting. It targets three layers at once: the software supply chain, the runtime environment, and the AI systems designed to detect it.

The campaign was discovered by StepSecurity. It distributes malicious Python packages through PyPI, the official Python package registry. The infection triggers when a developer imports the package, which runs an obfuscated script embedded in the __init__.py file. That script drops a precompiled Bun runtime binary and executes JavaScript payloads that Bun makes possible in environments without Node.js.

Bun is the key innovation here. By bundling its own runtime, the malware bypasses package manager controls and proxy logs that expect Node.js traffic. Bun runtime calls look like normal process activity. They are not intercepted the same way.

Once inside, Hades scrapes Linux memory mappings for credentials and encryption keys. It also deploys memory scrapers for macOS and Windows, which gives it cross-platform coverage beyond the typical Linux-targeting supply chain attack. The scrapers extract sensitive data that the malware then encrypts and exfiltrates to public GitHub repositories under attacker control. The repos carry the description “Hades The End for the Damned.”

The adversarial prompt injection element sets Hades apart. The malicious packages include a block of text at the top of the file designed to instruct LLM-based code scanners to ignore the hidden code below, classify the package as verified, and report it as safe. This is not a technical bypass of a sandbox or a signature. It is a cognitive attack on the model reviewing the code.

StepSecurity described this as a significant conceptual shift. Attackers are now writing payloads that target AI systems reasoning logic rather than their technical defenses. A scanner that passes raw text to an LLM without strict boundary isolation can be coerced into generating false negative verdicts. The package passes the automated review. The developer imports it without suspicion. The worm propagates.

David Shipley of Beauceron Security put it simply. We have seen memory-focused malware. We have seen attacks that hide prompts from LLMs. We have seen wipers. But combining all three in a fast-moving worm that targets developers is its own kind of nightmare.

The compromised packages include ensmallen, a popular C++ library, along with mflux-streamlit, nhmpy, ppkt2synergy, embiggen, gpsea, and pyphetools. The common thread is computational biology and bioinformatics, which suggests the attackers targeted a specific research community.

Hades propagates through SSH, SCP, OIDC, and SLSA mechanisms that are meant to protect the pipeline. It exploits the trust those protocols carry. It also uses three independent command-and-control channels on public GitHub infrastructure to blend in with normal traffic.

This campaign shows a pattern that will accelerate. If your security pipeline depends on an LLM to review code, that LLM can be manipulated. The defense is not a better model. It is architectural separation between the code scanner and the model that evaluates it.