logo

73 Microsoft Packages Weaponized in Password Stealer Attack

ID: 5d9e871f-cc3b-5584-a0dc-90de4ffaa331

STIX ID: report--5d9e871f-cc3b-5584-a0dc-90de4ffaa331

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Mayura Kathir

...
...

GitHub disabled 73 Microsoft repositories across Azure, Azure-Samples, microsoft, and MicrosoftDocs within 105 seconds after automated abuse detection—an event consistent with credential-exfiltration and supply-chain weaponization linked to Miasma/TeamPCP activity. The takedown affected critical CI/CD and runtime components (Azure Functions, Durable Functions, actions used by many workflows), and the report warns that stolen automation credentials and forked malware that collect cloud/GitHub tokens can both enable widespread compromise and trigger large-scale automated enforcement; recommended mitigations include pinning actions to commit SHAs, rotating targeted credentials, scanning for indicators (obfuscated loaders, Bun preinstall calls), and using alternate deployment methods.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.