logo

Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

ID: 17271b85-5d52-5f03-837c-e0f910ec1c6f

STIX ID: report--17271b85-5d52-5f03-837c-e0f910ec1c6f

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-06-06

Date Updated: 2026-06-06

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** The report describes the Miasma supply-chain campaign — a self-replicating worm variant of Mini Shai-Hulud — which has infected dozens of public repositories (including 73 Microsoft repos across multiple orgs) and re-compromised the durabletask package to deliver an information stealer; the actor persists by committing a staged payload to repositories and leveraging developer tools and AI coding agents to execute and propagate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.