Miasma Worm Compromises 73 Microsoft GitHub Repositories
ID: 1906012f-0ccb-59b7-99eb-2a5c995e8cd9
STIX ID: report--1906012f-0ccb-59b7-99eb-2a5c995e8cd9
Feed Name: Security Affairs
**Executive Summary:** The Miasma worm — an evolved Mini Shai-Hulud variant tied to TeamPCP — compromised 73 Microsoft GitHub repositories and abused stolen GitHub/OIDC credentials to publish malicious packages and plant droppers that execute when infected repositories are opened in popular AI coding tools; it harvests developer and CI/CD cloud credentials (Azure, GCP), evades hash-based detection by producing uniquely encrypted payloads per infection and leverages valid SLSA provenance to appear legitimate, and has re-compromised previously affected Durable Task projects indicating credential persistence and high supply-chain risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
