2026-06-09 / Signal #1
Miasma/Hades supply-chain malware injected into Microsoft open-source AI dev tools (Claude Code, Gemini CLI, VS Code extensions, Azure projects) that lies to AI security agents via prompt injection.
“The malware didn't just steal your passwords—it taught itself how to lie to the AI that's supposed to catch it.”
Why It Matters
Concrete artifact (malware in the exact tools AI builders use daily) showing AI agents/security being gamed/deceived; shifts builder behavior toward paranoia about OSS supply chains and "AI analysts" that can be gaslit. Weird future where code itself fights back against the machines meant to secure it.
Evidence
TechCrunch/404 Media/StepSecurity blogs (June 8, 2026), Cloudsmith/OpenSourceMalware analysis, HN top story (~265 pts); tied to Hades Campaign on PyPI that worms, scrapes memory, plants adversarial prompts in AI agent configs (Claude, Copilot, Aider, etc.), re-compromised prior Durable Task repo from May.
Signal Read
Source Trail
Daily scan: 2026-06-09