logo

Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories

ID: 5d8aa8ab-3dc7-54a1-917d-1eb471b1b73b

STIX ID: report--5d8aa8ab-3dc7-54a1-917d-1eb471b1b73b

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-06-09

Date Updated: 2026-06-15

Author: Rob Wright

...
...

A self-propagating worm (Miasma, a Shai-Hulud variant) automatedly compromised Microsoft GitHub repos and previously poisoned PyPI packages to plant credential-stealing malware and a modular intrusion framework that targets AI coding agents (Anthropic Claude Code, Google Gemini CLI, Cursor, VS Code). The attack disrupted CI/CD pipelines worldwide, allowed rapid token exfiltration and re-compromise of contributor accounts, and used config files (rather than modifying source code or packages) to bypass traditional detections; organizations that opened affected repos are advised to assume compromise, rotate credentials, and audit packages and AI-agent config files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.