Skip to main content
Mallory
Back to intelligence
package-repository-poisoningbuild-pipeline-compromisecredential-stealer-activitycommand-and-control-method

GitHub Disabled 70+ Microsoft Repos After Miasma Supply-Chain Malware Hit AI Dev Tools

Updated 27m agoFirst seen Jun 8, 202617 sources

GitHub disabled more than 70 Microsoft-owned repositories after detecting a suspected Miasma worm campaign that inserted malicious code into open source projects and disrupted dependent CI/CD workflows. Researchers said the incident began with a compromised contributor account pushing a malicious commit to Azure/durabletask, adding configuration files that could trigger remote code execution when developers opened the repository in IDEs or AI coding tools including Claude Code, Gemini CLI, and Cursor. Microsoft’s response was unusual because it shut down its own repositories rather than only removing the offending content, and GitHub reportedly disabled 73 repositories in rapid succession after automated detections fired.

The activity appears tied to a broader supply-chain operation linked to earlier compromises of Microsoft’s durabletask PyPI package and to a newer campaign tracked by StepSecurity as Hades, which it describes as an evolution of Miasma. StepSecurity said the malware uses obfuscated Python import hooks to fetch additional payloads, scrape memory across Linux, macOS, and Windows, steal cloud and developer credentials, abuse GitHub Actions and OIDC/Sigstore workflows, move laterally over SSH/SCP, and backdoor IDE and AI assistant configuration files. The campaign also reportedly uses GitHub-based command-and-control and includes a token-monitoring component that can trigger a destructive wiper if a stolen GitHub token is revoked, underscoring the risk to software supply chains and AI-assisted development environments.

Share:
GitHub Disabled 70+ Microsoft Repos After Miasma Supply-Chain Malware Hit AI Dev Tools
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jun 10, 20264h ago

Attackers publish 32 malicious npm packages via Red Hat namespace abuse

Researchers said the Miasma campaign compromised a Red Hat employee’s GitHub account, abused the @redhat-cloud-services npm namespace, and used legitimate GitHub OIDC tokens to publish 32 malicious npm package versions with valid SLSA provenance attestations. The releases appeared trusted to standard scanners, illustrating a supply-chain trust abuse rather than exploitation of a GitHub or npm vulnerability.

Developers urged to remain vigilant amid continued Miasma malware risks | IT Pro
Jun 9, 20262d ago

Microsoft says all affected GitHub repos were restored and are safe

Microsoft said that after its investigation, all affected repositories disabled on June 5 were restored and are now considered clean and safe to use. The statement updates the earlier status in which only some repositories had been restored while others remained offline.

GitHub disables Microsoft repos pushing password-stealing malware
Jun 8, 20263d ago

Microsoft restores some repos and notifies potentially affected customers

Microsoft said some of the disabled GitHub-hosted repositories were restored after review while others remained offline during the investigation. The company also said it notified a small number of potentially affected customers about the compromise.

Microsoft's open source tools were hacked to steal passwords of AI developers | TechCrunch

StepSecurity demo detects malware reading GitHub Actions runner memory

During a demonstration run, StepSecurity reported that its Harden-Runner product detected and blocked the malware's attempt to read GitHub Actions Runner.Worker memory. This provided an observed example of the campaign's credential- and secret-theft behavior.

The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent - StepSecurity

StepSecurity identifies Hades Campaign PyPI compromises

On June 8, multiple PyPI packages, including ensmallen 0.8.101, were identified as compromised in a supply-chain operation tracked as the Hades Campaign. StepSecurity described the campaign as an evolution of the Miasma threat actor using obfuscated import hooks, GitHub-based C2 and exfiltration, SSH/SCP worm-like spread, GitHub Actions abuse, and AI-tooling backdoors.

The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent - StepSecurity

Compromised contributor account pushes malicious commit to Azure/durabletask

The incident was reported to have begun when a compromised contributor account pushed a malicious commit to Azure/durabletask. The commit added configuration files that could trigger remote code execution when developers opened the repository in IDEs or AI coding tools such as Claude Code, Gemini CLI, and Cursor.

GitHub nukes 70+ Microsoft repos amid suspected worm attack
Jun 5, 20266d ago

GitHub disables 73 Microsoft repositories after worm detections

On June 5, automated detections triggered a takedown of Microsoft repositories after signs of the Miasma worm were found. Reporting says GitHub disabled 73 repositories in two waves within 105 seconds, disrupting CI/CD pipelines including dependencies on Azure/functions-action@v1.

GitHub nukes 70+ Microsoft repos amid suspected worm attack
May 19, 202623d ago

Malicious durabletask package versions published to PyPI

A prior supply-chain attack on Microsoft's durabletask PyPI package occurred on May 19, with malicious versions reported to plant infostealers targeting cloud secrets and developer tool configurations on Linux systems. Later reporting linked this event to the Miasma worm activity.

GitHub nukes 70+ Microsoft repos amid suspected worm attack

Researcher creates Antimiasma and anti-worm mitigation tools

The author of the new report said they developed an Antimiasma mitigation tool and a separate anti-worm capability in response to the Miasma campaign. This represents a new defensive response aimed at countering the malware's spread and impact.

Malware Insights: Miasma Campaign | Cookie Engineer's Weblog
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.