9 Sources
[1]
For the 2nd time in weeks, Microsoft packages laced with credential stealer
Dozens of cryptographically verified open source packages from Microsoft were compromised late last week to add advanced credential-stealing code that was triggered when developers opened them in AI coding agents. In all, multiple researchers said, 73 packages were flagged as malicious when
[2]
GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections
Microsoft's GitHub has disabled over 70 repositories after they were reportedly compromised by a worm in the latest open source supply chain attack. The code shack took down 73 repos within the space of 105 seconds after its alarms were tripped on Friday, June 5, after detecting signs of the
[3]
GitHub disables Microsoft repos pushing password-stealing malware
Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub, disrupting continuous integration pipelines. The incident occurred on June 5, and it was contained within just 105 seconds. The company told BleepingComputer that the
[4]
Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
Microsoft on Monday confirmed that it temporarily removed some GitHub repositories in response to a recent security incident that led to 73 of its open-source projects being compromised to inject an information stealer into the code. "Our priority is to protect customers and the broader
[5]
Self-replicating Miasma worm hits 73 Microsoft GitHub repositories in supply chain attack
The Miasma worm hit 73 Microsoft GitHub repos across Azure and Microsoft orgs. It plants payloads that trigger in AI coding tools like Claude Code and Cursor. The self-replicating Miasma worm has reached Microsoft's own GitHub repositories. GitHub disabled 73 repositories across four Microsoft
[6]
Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
Microsoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories across four of its GitHub organizations, including Azure, Azure-Samples, Microsoft, and MicrosoftDocs, per
[7]
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm, respectively. According to JFrog, the information stealer
[8]
Microsoft Open Source Security Breach, Dozens of GitHub Repos Pulled After Malware Discovery
Microsoft has taken several GitHub projects offline after hackers slipped malware into open-source code. The attack may have exposed passwords and other sensitive data used by developers working on AI projects. Microsoft is exposed to a new security risk as hackers may have managed to place
[9]
Hackers exploit Microsoft open-source software to steal AI developers passwords
The company is investigating the breach and has alerted a small number of impacted users. Microsoft has temporarily taken down dozens of its open-source projects from GitHub after discovering a security incident that may have exposed users to password-stealing malware. The move comes after
Share
Copy Link
Microsoft removed 73 GitHub repositories after they were infected with the Miasma worm, a self-replicating credential-stealing malware that activates when developers open projects in AI coding tools. The attack exploited the same compromised credentials from a May breach, raising questions about incomplete credential rotation and highlighting vulnerabilities in the modern software supply chain.
Microsoft GitHub repositories fell victim to a sophisticated supply chain attack last week when 73 projects across Azure, Microsoft, Azure-Samples, and MicrosoftDocs organizations were compromised with credential-stealing malware
1
. GitHub's automated systems flagged and disabled all affected repositories within 105 seconds on June 5, though the platform initially cited only "a violation of GitHub's terms of service" without acknowledging the security breach2
. This marks the second time in as many months that an official Microsoft repository account has been breached, with the same durabletask package targeted in both incidents1
.
Source: Hacker News
The Miasma malware deployed in this cybersecurity incident represents an evolution in supply chain attacks, specifically engineered to exploit AI coding tools including Claude Code, Gemini CLI, Cursor, and VS Code
5
. The attack began when a compromised contributor account pushed a malicious commit to Azure/durabletask, dropping configuration files that triggered remote code execution the moment a developer opened the repository in an IDE or AI coding agent2
. The password-stealing malware executes a 28 KB payload that harvests credentials from AWS, Azure, GCP, Kubernetes, password managers, and over 90 developer tool configurations1
. Once activated, the worm spreads laterally through cloud infrastructures to infect other developer machines, using stolen tokens to commit itself into any repository the victim can write to5
.
Source: Hacker News
The attack has been linked to TeamPCP, a threat actor that recently open-sourced the Mini Shai-Hulud toolkit upon which the Miasma malware is based
1
. However, because TeamPCP released the source code publicly, security researchers cannot definitively confirm whether the group itself executed this attack or if other actors leveraged the toolkit2
. The original Shai-Hulud worm first appeared in September 2025 as the first self-replicating malware observed in the npm ecosystem, and has since mutated across npm and PyPI platforms, previously compromising 32 Red Hat packages5
. The software supply chain campaign has also infected packages from TanStack, Mistral AI, and UiPath, with more than 80 public repositories on GitHub carrying the Miasma campaign's naming pattern5
.What makes this information stealer particularly insidious is that it doesn't exploit software vulnerabilities in GitHub or npm
1
. According to Cloudsmith, the attack exploits the underlying trust model of the modern engineering ecosystem by stealing legitimate maintainer credentials and using them to request valid GitHub OIDC tokens1
. The malicious builds were published with valid SLSA provenance attestation, causing conventional scanners to see them as routine trusted updates1
. The Miasma worm generates a uniquely encrypted payload for each individual infection, rendering traditional hash-based indicators of compromise functionally useless for broad detection1
.The removal of compromised open-source packages caused immediate disruption to development workflows, particularly affecting Azure/functions-action, a GitHub Action used by developers to deploy code to Azure
2
. Every workflow referencing Azure/functions-action@v1 stopped resolving when the repository was taken down, breaking CI/CD pipelines for numerous developers2
. Microsoft confirmed it "notified a small number of customers who may have pulled down content from the affected repositories" and stated that some repositories have been restored after review while others remain offline pending investigation4
. The durabletask package on PyPI, which receives 400,000 downloads per month, was previously compromised on May 19 when three malicious versions were uploaded within a 35-minute window1
.
Source: Hacker News
Related Stories
The fact that the same Microsoft GitHub account was compromised twice raises critical questions about credential rotation practices
1
. Security researcher Paul McCarty noted that "when the repo at the root of last month's compromise is the hub of this month's takedown, that is not a coincidence, that is the same wound reopening"5
. StepSecurity's analysis suggests the re-targeting of durabletask indicates that tokens associated with the compromised developer account used in the PyPI attack were not fully rotated, allowing attackers to push commits to GitHub2
. Alternative explanations include re-compromise through the worm's own propagation loop or the use of a different contributor's token with altered metadata to disguise the attack2
.The targeting of AI coding tools represents a notable evolution in supply chain attacks, exploiting behavior patterns that didn't exist a year ago
5
. Developers increasingly rely on tools like Claude Code and Cursor to work with unfamiliar repositories, and the worm activates precisely when an AI agent opens a project5
. Recent analysis uncovered a newer PyPI wave tied to the broader Mini Shai-Hulud, Miasma, and Hades waves, infecting an additional 23 packages including bioinformatics-related libraries and AI-themed packages4
. Socket reported that the latest cluster employs new payload delivery mechanisms, including trojanized native .abi3.so extensions that execute the stealer when packages are imported, indicating threat actors are actively experimenting with different methods4
. Security experts recommend that software developers lock project dependencies, add multi-day time delays to fetch new package updates, and test new builds on isolated environments3
.Summarized by
Navi
[2]
[3]
21 May 2026•Technology

12 May 2026•Technology

28 Aug 2025•Technology
