logo

Miasma worm targets Microsoft, compromises 73 GitHub repositories

ID: f6a6f4c5-17ab-5680-9022-e9546b466058

STIX ID: report--f6a6f4c5-17ab-5680-9022-e9546b466058

Feed Name: ThreatLocker Blog

Threat Score
85/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

...
...

On 2026-06-05 the Microsoft-owned Azure/durabletask GitHub repository was compromised via a malicious commit that contained obfuscated JavaScript and configuration designed to execute when the repository was opened; the payload executed immediately, searched for specific CI/sandboxing components to evade detection, and exfiltrated secrets from GitHub, AWS, Azure, and GCP to attacker-controlled GitHub repositories labeled with Hades-themed names. The report provides TTPs, SHA256 hashes for malicious artifacts, network and host IOCs (domains, IP, file paths, service names), and mitigation steps including credential rotation, artifact detection, and endpoint/cloud audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.