GitHub disables Microsoft repos pushing password-stealing malware
ID: 89a625be-e6dc-5d93-8df3-9e3c94b87e71
STIX ID: report--89a625be-e6dc-5d93-8df3-9e3c94b87e71
Feed Name: Bleeping Computer
Microsoft temporarily removed and later restored 73 GitHub repositories after they were identified as potentially distributing malicious content linked to the Miasma/Shai-Hulud supply-chain campaign. The compromise affected Azure-related repos (notably disabling an Azure Functions GitHub Action) and follows earlier malicious PyPI package uploads (durabletask 1.4.1–1.4.3); researchers tie the activity to a worm-like campaign that targeted developer tooling and open-source ecosystems, causing CI outages and prompting recommendations to lock dependencies and test updates in isolated environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
