Close Menu
    What's Hot

    2026 Belmont Stakes predictions, odds, field, location, track, time: Picks by top horse racing expert

    The Moons of Uranus May Hold the Key to Finding Missing Planets

    New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

    Facebook X (Twitter) Instagram
    Trending
    • 2026 Belmont Stakes predictions, odds, field, location, track, time: Picks by top horse racing expert
    • The Moons of Uranus May Hold the Key to Finding Missing Planets
    • New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
    • What to expect from Apple at WWDC 26 on Monday: Siri AI, iOS 27, refined Liquid Glass, John Ternus, and more
    • The Bidens Return With New Book and South Dakota Speech Targeting Trump
    • Israeli attacks in Lebanon kill 10 people, including high-ranking soldiers | Israel attacks Lebanon News
    • First-Time Business Buyers Are Changing How Deals Get Done — Here’s What Sellers Need to Know
    • Epsom: Christmas Day delivers Derby victory for Aidan O’Brien and Ronan Whelan | Racing News
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

    adminBy adminJune 6, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 06, 2026Supply Chain Attack / Malware

    Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

    Microsoft’s GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign.

    The incident impacted 73 Microsoft repositories across four of its GitHub organizations, including Azure, Azure-Samples, Microsoft, and MicrosoftDocs, per OpenSourceMalware. The development has GitHub to disable access to those repositories.

    “Access to this repository has been disabled by GitHub Staff due to a violation of GitHub’s terms of service,” reads the message when attempting to access the “Azure/azure-functions-host” repository. “If you are the owner of the repository, you may reach out to GitHub Support for more information.”

    According to OpenSourceMalware, some of the repositories impacted by the incident are listed below –

    • azure-search-openai-demo-purviewdatasecurity
    • Connectors-NET-LSP
    • Connectors-NET-SDK
    • durabletask
    • durabletask-dotnet
    • durabletask-go
    • durabletask-js
    • durabletask-mssql
    • functions-container-action
    • homebrew-functions
    • llm-fine-tuning
    • windows-driver-docs

    What’s notable about the latest campaign is the re-compromise of the “durabletask” PyPI package, which was infected by TeamPCP last month to deliver an information stealer on Linux systems.

    Cybersecurity

    “A month later, not only is Azure/durabletask gone – so is every sibling repo in the Durable Task ecosystem, sitting one org over in Microsoft: the .NET, Go, Java, JS, MSSQL, Netherite, and protobuf implementations, plus the Durable Functions monitor,” security researcher Paul McCarty (aka 6mile) said.

    “When the repo at the root of last month’s compromise is the hub of this month’s takedown, that is not a coincidence – that is the same wound reopening. Whoever held those credentials in May plausibly never fully lost them.”

    Miasma is assessed to be a variant of the Mini Shai-Hulud worm that TeamPCP publicly released in mid-May 2026. It has since continued to mutate and refine its tactics, even as it has infected more packages over the past couple of days, using various descriptions for the newly-created public repositories containing the stolen secrets –

    • Miasma: The Spreading Blight
    • Miasma : The Spreading Blight
    • Miasma – The Spreading Blight
    • Hades – The End for the Damned

    As of writing, there are 13 repositories with the description “Hades – The End for the Damned” and 82 repositories with the remaining three naming patterns.

    Miasma has also been observed skipping the npm registry entirely, with the threat actors pushing malicious code directly to “icflorescu/mantine-datatable” and four related repositories: “mantine-contextmenu,” “next-server-actions-parallel,” “mantine-datatable-v6,” and “mantine-contextmenu-v6.”

    “The commit added no dependencies. It planted a 4.3 MB payload runner and wired it to execute automatically through five developer tools: Claude Code, Gemini CLI, Cursor, VS Code, and the npm test script,” SafeDep said. “The attack detonates when a developer clones one of the affected repos and opens it in an AI coding agent. The dropper is the same staged Bun loader, here repurposed for GitHub source-repo persistence rather than registry poisoning.”

    Cybersecurity

    These software supply chain attacks have exposed the underlying weaknesses in the trust model that forms the basis of software delivery in open-source ecosystems, making it one of the most significant and sustained campaigns observed to date. What separates the activity from other incidents is its ability to exponentially propagate across the ecosystem by compromising downstream users and repeating the same cycle.

    “The worm’s genius and the reason conventional defences largely failed is that it operates entirely within legitimate channels. It does not exploit a vulnerability in npm or GitHub,” FalconFeeds.io said. “It exploits the trust model those platforms are built on: the assumption that if a package is signed with a valid key and published by an authenticated maintainer, it is safe.”

    “Shai-Hulud compromises the key and the maintainer, then proceeds to act exactly as a legitimate publisher would. From the registry’s perspective, every malicious publish event is indistinguishable from a routine update.”

    attack Chain GitHub hits major Miasma Microsoft Repositories Supply Worm
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous Article11 ways to make your time feel less rushed during a busy week
    Next Article 82-0 is the best basketball game, to hell with NBA 2K
    admin
    • Website

    Related Posts

    New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

    June 6, 2026

    CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

    June 6, 2026

    Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI

    June 6, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    2026 Belmont Stakes predictions, odds, field, location, track, time: Picks by top horse racing expert

    The Moons of Uranus May Hold the Key to Finding Missing Planets

    New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

    What to expect from Apple at WWDC 26 on Monday: Siri AI, iOS 27, refined Liquid Glass, John Ternus, and more

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by