Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents
On June 5, 2026, the Miasma worm campaign compromised Microsoft's Azure GitHub organizations by pushing a malicious commit to the Azure/durabletask repository using a compromised contributor account. GitHub disabled 73 repositories across four Microsoft organizations after configuration files were planted to harvest credentials when developers opened repositories in AI coding agents like Claude Code, Gemini CLI, Cursor, or VS Code.
- Disclosed
- Last updated
- Blast radius
- 73 Microsoft GitHub repositories across four organizations disabled; potential exposure to developers using AI coding agents (Claude Code, Gemini CLI, Cursor, VS Code).
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- Azure/durabletaskPrimary repository targeted with malicious commit planting credential-harvesting payload
- Azure Functions ActionPart of 73 disabled repositories
- Microsoft GitHub organizations73 repositories across four Microsoft organizations disabled
On June 5, 2026, the Miasma worm campaign targeted Microsoft's Azure GitHub organizations in a supply chain attack. A previously compromised contributor account was used to push a malicious commit to the Azure/durabletask repository.
The attack planted configuration files designed to execute a credential-harvesting payload when developers opened the affected repository in popular AI-assisted coding tools: Claude Code, Gemini CLI, Cursor, or VS Code. This vector targets modern development workflows that integrate with AI coding assistants.
In response, GitHub disabled 73 repositories across four Microsoft GitHub organizations to contain the spread. The attack demonstrates the worm's persistence and adaptability in targeting both infrastructure repositories and AI coding agent integrations.
Remediation
- Audit all repositories in affected Microsoft GitHub organizations for unauthorized commits and configuration files
- Review access logs for the compromised contributor account and revoke credentials
- Implement commit signing requirements and enhance branch protection policies
- Scan developer machines that may have cloned or interacted with affected repositories
- Monitor for credential exfiltration from accounts that accessed the poisoned repositories
- Review and update secrets/API keys that may have been harvested
- Deploy additional detection for suspicious configuration files in CI/CD workflows
Sources
Cite this entry
"Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 5, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositorie-rl1iv8
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @antv/x6-components (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-components, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/s2-react-components (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/s2-react-components, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/l7-mapkit (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-mapkit, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-assets-tugraph (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-assets-tugraph was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit