Miasma worm targets Microsoft, compromises 73 GitHub repositories
ID: f6a6f4c5-17ab-5680-9022-e9546b466058
STIX ID: report--f6a6f4c5-17ab-5680-9022-e9546b466058
Feed Name: ThreatLocker Blog
On 2026-06-05 the Microsoft-owned Azure/durabletask GitHub repository was compromised via a malicious commit that contained obfuscated JavaScript and configuration designed to execute when the repository was opened; the payload executed immediately, searched for specific CI/sandboxing components to evade detection, and exfiltrated secrets from GitHub, AWS, Azure, and GCP to attacker-controlled GitHub repositories labeled with Hades-themed names. The report provides TTPs, SHA256 hashes for malicious artifacts, network and host IOCs (domains, IP, file paths, service names), and mitigation steps including credential rotation, artifact detection, and endpoint/cloud audits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
