logo

Miasma Worm Compromises 73 Microsoft GitHub Repositories

ID: 1906012f-0ccb-59b7-99eb-2a5c995e8cd9

STIX ID: report--1906012f-0ccb-59b7-99eb-2a5c995e8cd9

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-06-09

Date Updated: 2026-06-10

Author: Pierluigi Paganini

...
...

**Executive Summary:** The Miasma worm — an evolved Mini Shai-Hulud variant tied to TeamPCP — compromised 73 Microsoft GitHub repositories and abused stolen GitHub/OIDC credentials to publish malicious packages and plant droppers that execute when infected repositories are opened in popular AI coding tools; it harvests developer and CI/CD cloud credentials (Azure, GCP), evades hash-based detection by producing uniquely encrypted payloads per infection and leverages valid SLSA provenance to appear legitimate, and has re-compromised previously affected Durable Task projects indicating credential persistence and high supply-chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.