Socket researchers discovered 37 malicious Python packages leveraging “.pth” files to execute a Bun-powered JavaScript credential stealer at Python startup. The attack, attributed to the Shai-Hulud/Miasma threat group, targets high-value developer and CI/CD secrets across multiple ecosystems using GitHub-based exfiltration with Hades-themed markers. Affected packages included widely-used bioinformatics tools with hundreds of thousands of cumulative downloads.