PulseAugur
EN
LIVE 23:20:16

AI coding tools targeted by evolving 'Hades' malware campaign

A sophisticated cyberattack campaign, tracked as UNC6780 or TeamPCP, has evolved to target AI coding tools, including Claude Code. The malware, now named "Hades: The End for the Damned," spreads through Python and manipulates AI assistants by planting malicious instructions in their configuration files. This campaign has already compromised thousands of machines, stolen hundreds of thousands of secrets, and even breached GitHub's internal repositories, with the attackers open-sourcing their methods and offering bounties, leading to widespread adoption and new variants. AI

IMPACT This evolving malware campaign directly targets AI coding assistants, creating a new attack surface that bypasses traditional security measures and potentially compromises sensitive data.

RANK_REASON The cluster details a significant evolution in cyberattack methods targeting AI coding tools, posing a widespread security risk. [lever_c_demoted from significant: ic=1 ai=0.8]

Read on r/ClaudeAI →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

AI coding tools targeted by evolving 'Hades' malware campaign

How we ranked this

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Research
The cluster details a significant evolution in cyberattack methods targeting AI coding tools, posing a widespread security risk. [lever_c_demoted from significant: ic=1 ai=0.8]
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product, other
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
108 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

Full methodology in our editorial standards.

COVERAGE [1]

  1. r/ClaudeAI TIER_2 English(EN) · /u/johnypita ·

    The Claude Code active attack didn't stop. 294,842 secrets stolen from 6,943 machines. It evolved and now spreads through Python too and uses Claude Code itself to steal your secrets. The risk to your credentials just got bigger.

    <!-- SC_OFF --><div class="md"><p>TLDR: Anthropic shipped Fable 5. They call this model class the strongest cyber capability in the world and lock the uncapped version to government defenders. This post is the other side of this, the same power pointed at you.</p> <p>I posted abo…