GitHub disabled more than 70 Microsoft-owned repositories after detecting a suspected Miasma worm campaign that inserted malicious code into open source projects and disrupted dependent CI/CD workflows. Researchers said the incident began with a compromised contributor account pushing a malicious commit to Azure/durabletask, adding configuration files that could trigger remote code execution when developers opened the repository in IDEs or AI coding tools including Claude Code, Gemini CLI, and Cursor. Microsoft’s response was unusual because it shut down its own repositories rather than only removing the offending content, and GitHub reportedly disabled 73 repositories in rapid succession after automated detections fired.
The activity appears tied to a broader supply-chain operation linked to earlier compromises of Microsoft’s durabletask PyPI package and to a newer campaign tracked by StepSecurity as Hades, which it describes as an evolution of Miasma. StepSecurity said the malware uses obfuscated Python import hooks to fetch additional payloads, scrape memory across Linux, macOS, and Windows, steal cloud and developer credentials, abuse GitHub Actions and OIDC/Sigstore workflows, move laterally over SSH/SCP, and backdoor IDE and AI assistant configuration files. The campaign also reportedly uses GitHub-based command-and-control and includes a token-monitoring component that can trigger a destructive wiper if a stolen GitHub token is revoked, underscoring the risk to software supply chains and AI-assisted development environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Researchers said the Miasma campaign compromised a Red Hat employee’s GitHub account, abused the @redhat-cloud-services npm namespace, and used legitimate GitHub OIDC tokens to publish 32 malicious npm package versions with valid SLSA provenance attestations. The releases appeared trusted to standard scanners, illustrating a supply-chain trust abuse rather than exploitation of a GitHub or npm vulnerability.
Microsoft said that after its investigation, all affected repositories disabled on June 5 were restored and are now considered clean and safe to use. The statement updates the earlier status in which only some repositories had been restored while others remained offline.
Microsoft said some of the disabled GitHub-hosted repositories were restored after review while others remained offline during the investigation. The company also said it notified a small number of potentially affected customers about the compromise.
During a demonstration run, StepSecurity reported that its Harden-Runner product detected and blocked the malware's attempt to read GitHub Actions Runner.Worker memory. This provided an observed example of the campaign's credential- and secret-theft behavior.
On June 8, multiple PyPI packages, including ensmallen 0.8.101, were identified as compromised in a supply-chain operation tracked as the Hades Campaign. StepSecurity described the campaign as an evolution of the Miasma threat actor using obfuscated import hooks, GitHub-based C2 and exfiltration, SSH/SCP worm-like spread, GitHub Actions abuse, and AI-tooling backdoors.
The incident was reported to have begun when a compromised contributor account pushed a malicious commit to Azure/durabletask. The commit added configuration files that could trigger remote code execution when developers opened the repository in IDEs or AI coding tools such as Claude Code, Gemini CLI, and Cursor.
On June 6, SafeDep published an analysis of an allegedly open-sourced Miasma release, describing it as a broad software supply-chain attack toolkit rather than only a worm. The report detailed GitHub-based command-and-control and exfiltration, OIDC trusted-publishing abuse, GitHub Actions tag hijacking, pull-request branch poisoning, AWS SSM lateral movement, runner memory scraping, a dead-man-switch wipe feature, and multi-layer payload obfuscation.
On June 5, automated detections triggered a takedown of Microsoft repositories after signs of the Miasma worm were found. Reporting says GitHub disabled 73 repositories in two waves within 105 seconds, disrupting CI/CD pipelines including dependencies on Azure/functions-action@v1.
A prior supply-chain attack on Microsoft's durabletask PyPI package occurred on May 19, with malicious versions reported to plant infostealers targeting cloud secrets and developer tool configurations on Linux systems. Later reporting linked this event to the Miasma worm activity.
The author of the new report said they developed an Antimiasma mitigation tool and a separate anti-worm capability in response to the Miasma campaign. This represents a new defensive response aimed at countering the malware's spread and impact.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
20 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcethenewstack.io
Open sourcecybersecuritynews.com
Open sourceitpro.com
Open sourcetechcrunch.com
Open sourcesafedep.io
Open sourceopensourcemalware.com
Open sourcecookie.engineer
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.