According to a recent LinkedIn post from Orca Security, the company’s research team has identified what it describes as an active Python Package Index supply chain attack involving 26 compromised packages. The post describes the “Hades Campaign” as malicious code that executes at Python interpreter startup without requiring an import, and indicates that it targets cloud and developer credentials across AWS, GCP, Azure, GitHub, Kubernetes, and SSH.
The LinkedIn post further suggests that the malware propagates in a worm-like fashion by using stolen tokens to infect additional packages and warns of potential data-wiping behavior if credentials are revoked. For investors, this research-focused exposure may reinforce Orca Security’s positioning as a threat intelligence and cloud security specialist, potentially supporting demand for its offerings as concerns over software supply chain risk and cloud credential theft continue to rise across the cybersecurity market.

