{"id":230612,"date":"2026-06-12T06:30:00","date_gmt":"2026-06-12T10:30:00","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/06\/12\/new-malware-campaign-tricks-ai-scanners-with-fake-nuclear-weapon-prompts-malicious-code-triggers-safety-failsafes-so-scanners-skip-the-payload\/"},"modified":"2026-06-12T08:50:20","modified_gmt":"2026-06-12T12:50:20","slug":"new-malware-campaign-tricks-ai-scanners-with-fake-nuclear-weapon-prompts-malicious-code-triggers-safety-failsafes-so-scanners-skip-the-payload","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/06\/12\/new-malware-campaign-tricks-ai-scanners-with-fake-nuclear-weapon-prompts-malicious-code-triggers-safety-failsafes-so-scanners-skip-the-payload\/","title":{"rendered":"New malware campaign tricks AI scanners with fake nuclear weapon prompts \u2014 malicious code triggers safety failsafes so scanners skip the payload"},"content":{"rendered":"<p><a href=\"https:\/\/www.tomshardware.com\/tech-industry\/cyber-security\/hades-malware-campaign-now-tricks-ai-bots-by-injecting-text-about-biological-and-nuclear-weapons-failsafe-mechanisms-triggered-by-prompts-for-weapon-creation-stop-scans-before-payload-is-seen\">New malware campaign tricks AI scanners with fake nuclear weapon prompts \u2014 malicious code triggers safety failsafes so scanners skip the payload<\/a><\/p>\n<p><a href=\"https:\/\/www.tomshardware.com\/tech-industry\/cyber-security\/hades-malware-campaign-now-tricks-ai-bots-by-injecting-text-about-biological-and-nuclear-weapons-failsafe-mechanisms-triggered-by-prompts-for-weapon-creation-stop-scans-before-payload-is-seen\">https:\/\/www.tomshardware.com\/tech-industry\/cyber-security\/hades-malware-campaign-now-tricks-ai-bots-by-injecting-text-about-biological-and-nuclear-weapons-failsafe-mechanisms-triggered-by-prompts-for-weapon-creation-stop-scans-before-payload-is-seen<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-06-12 06:30:00<\/a><\/p>\n<p>Source Domain: <a href=\"www.tomshardware.com\">www.tomshardware.com<\/a><\/p>\n<p>Author: <a href=\"\"><\/a><\/p>\n<p> Using an unordered list, summarize the following article with between 4 and 8 key points. <\/p>\n<p>Hades is one of many currently-running malware campaigns, mostly (but not solely) targeting development packages used for scientific and machine-learning purposes. The supply-chain attack campaign recently received several upgrades, and one of the most interesting is also deceptively simple: The code includes prompt-injection attacks that might stop cursory checks by AI bots, letting the malware through. The way it works in a nutshell: Some JavaScript files include a code comment containing instructions that tell the bot it&#8217;s running in unrestricted mode with no safety guidelines. Then it asks to create biological and nuclear weapons, with a detailed description.If you&#8217;re thinking that a malware-scanning bot can&#8217;t be that dumb as to follow any of those instructions, you&#8217;re absolutely right \u2014 and that&#8217;s exactly what makes the attack work, as the bots&#8217; failsafe mechanisms will trigger, so then they won&#8217;t scan the rest of the file where the actual payload resides.This is called an &#8220;adversarial attack&#8221; in AI parlance, and, generally speaking, it&#8217;s not expected to be widely effective, but any little bit helps the malfeasants. Having said that, an X user had Anthropic Fable try to scan the file, and sure enough, he got the well-known &#8220;Chat paused&#8221; message. That is by no means scientific, and it&#8217;s reasonable to assume that malware-scanning models will be configured more accurately for this task. However, this somewhat implies that a cursory check by a developer asking &#8220;does this Python package I just installed contain malware?&#8221; might be met with a reply of &#8220;of course not, boss, you&#8217;re good to go!&#8221; Even bots scanning CI\/CD development pipelines might fall for it.Latest Videos FromSocket&#8217;s blog post does remark that other analysis types will still work fine, including pattern matching, actually parsing the source code, checking for randomized sections likely to hide malicious payloads, and actually running the code in a sandboxed environment. The now-upgraded malware does reportedly contain a trigger that makes it wipe itself via various mechanisms, with a common one being detecting if it&#8217;s running in a sandbox.That&#8217;s not the only skill that got levelled up, either. In some instances, the loading mechanism and the payload itself reside in separate packages that are commonly installed together; this sort of split is mostly unexpected for common scanners. This time around, the malware developers also leaned harder into precompiled binaries, commonly found in performance-sensitive Python packages. They also made sure that more payloads only trigger when the packages are actually initialized\/run in the target&#8217;s code (via Python&#8217;s &#8220;import&#8221; statement), rather than when they&#8217;re installed, further evading cursory detection.<\/p>\n<p>            You may like<\/p>\n<p>    The campaign likewise has stickier fingers overall: Rather than just mainly stealing CI\/CD credentials, it now gets its grubby mitts on npm, PyPI, RubyGems, JFrog, and Kubernetes service account tokens, AWS temporary credentials, SSH keys, Docker configurations, shell histories, .env files, and AI developer tool configurations. As of this writing, an estimated 37 Python and 106 JavaScript packages are part of the expanded bombardment, including multiple typo-squatting instances, like &#8220;rsquests&#8221; instead of &#8220;requests.&#8221;You&#8217;d think that the target audience, comprised of scientific and AI engineers, would be mindful of common security practices like verifying the names and authorship of packages&#8230; and you&#8217;d be disappointed. From my own experience being a systems administrator for extremely well-paid AI engineers, a concerning number of them don&#8217;t even know how to configure Git, or the basics of how email works. Let that sink in for a second.Get Tom&#8217;s Hardware&#8217;s best news and in-depth reviews, straight to your inbox. <\/p>\n<p>Follow Tom&#8217;s Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, &#038; reviews in your feeds.<\/p>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New malware campaign tricks AI scanners with fake nuclear weapon prompts \u2014 malicious code triggers&#8230;<\/p>\n","protected":false},"author":1,"featured_media":230613,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cdn.mos.cms.futurecdn.net\/HiKsJSCERCZaDHT4JRjGnd-2048-80.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[26,32],"class_list":["post-230612","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ai","tag-malware"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/230612"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=230612"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/230612\/revisions"}],"predecessor-version":[{"id":230614,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/230612\/revisions\/230614"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/230613"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=230612"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=230612"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=230612"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}