GitHub disabled 73 Microsoft repositories across Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on June 5 after a Miasma/Shai-Hulud supply-chain attack injected password-stealing malware. The incident lasted only 105 seconds before containment, but disrupted CI/CD pipelines — notably breaking the 'Azure/functions-action' GitHub Action used to deploy Azure Functions. The same campaign previously compromised 32 Red Hat npm packages and also pushed malicious versions of the 'durabletask' package to PyPI. The attack vector involved compromising a Red Hat employee's GitHub account and injecting workflows that harvested OIDC tokens. All repositories have since been restored, and Microsoft notified affected customers. Researchers note the Miasma worm specifically targeted AI coding tools including Claude Code, Gemini CLI, VS Code, and Cursor. Developers are advised to lock dependencies, delay package updates, and test builds in isolated environments.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
356 Impressions