Close Menu
    What's Hot

    Nvidia Wants to Own Every Chip Inside AI Data Centers

    Patek Philippe Debuted the Nautilus 50 Years Ago

    These cities just became America’s hottest buyer’s markets

    Facebook X (Twitter) Instagram
    Trending
    • Nvidia Wants to Own Every Chip Inside AI Data Centers
    • Patek Philippe Debuted the Nautilus 50 Years Ago
    • These cities just became America’s hottest buyer’s markets
    • The Light Flip Is the Stylish Dumb Flip Phone of Your Dreams
    • Credo: The Buying Opportunity Is Finally Flashing (Rating Upgrade) (NASDAQ:CRDO)
    • When Protesters Speak, Zelensky Listens, in the Ukrainian Tradition
    • Old Firm pitch invasion: Rangers and Celtic charged by Scottish FA over trouble after Scottish Cup game at Ibrox | Football News
    • Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

    adminBy adminJune 6, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 06, 2026Supply Chain Attack / Malware

    Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

    Microsoft’s GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign.

    The incident impacted 73 Microsoft repositories across four of its GitHub organizations, including Azure, Azure-Samples, Microsoft, and MicrosoftDocs, per OpenSourceMalware. The development has GitHub to disable access to those repositories.

    “Access to this repository has been disabled by GitHub Staff due to a violation of GitHub’s terms of service,” reads the message when attempting to access the “Azure/azure-functions-host” repository. “If you are the owner of the repository, you may reach out to GitHub Support for more information.”

    According to OpenSourceMalware, some of the repositories impacted by the incident are listed below –

    • azure-search-openai-demo-purviewdatasecurity
    • Connectors-NET-LSP
    • Connectors-NET-SDK
    • durabletask
    • durabletask-dotnet
    • durabletask-go
    • durabletask-js
    • durabletask-mssql
    • functions-container-action
    • homebrew-functions
    • llm-fine-tuning
    • windows-driver-docs

    What’s notable about the latest campaign is the re-compromise of the “durabletask” PyPI package, which was infected by TeamPCP last month to deliver an information stealer on Linux systems.

    Cybersecurity

    “A month later, not only is Azure/durabletask gone – so is every sibling repo in the Durable Task ecosystem, sitting one org over in Microsoft: the .NET, Go, Java, JS, MSSQL, Netherite, and protobuf implementations, plus the Durable Functions monitor,” security researcher Paul McCarty (aka 6mile) said.

    “When the repo at the root of last month’s compromise is the hub of this month’s takedown, that is not a coincidence – that is the same wound reopening. Whoever held those credentials in May plausibly never fully lost them.”

    Miasma is assessed to be a variant of the Mini Shai-Hulud worm that TeamPCP publicly released in mid-May 2026. It has since continued to mutate and refine its tactics, even as it has infected more packages over the past couple of days, using various descriptions for the newly-created public repositories containing the stolen secrets –

    • Miasma: The Spreading Blight
    • Miasma : The Spreading Blight
    • Miasma – The Spreading Blight
    • Hades – The End for the Damned

    As of writing, there are 13 repositories with the description “Hades – The End for the Damned” and 82 repositories with the remaining three naming patterns.

    Miasma has also been observed skipping the npm registry entirely, with the threat actors pushing malicious code directly to “icflorescu/mantine-datatable” and four related repositories: “mantine-contextmenu,” “next-server-actions-parallel,” “mantine-datatable-v6,” and “mantine-contextmenu-v6.”

    “The commit added no dependencies. It planted a 4.3 MB payload runner and wired it to execute automatically through five developer tools: Claude Code, Gemini CLI, Cursor, VS Code, and the npm test script,” SafeDep said. “The attack detonates when a developer clones one of the affected repos and opens it in an AI coding agent. The dropper is the same staged Bun loader, here repurposed for GitHub source-repo persistence rather than registry poisoning.”

    Cybersecurity

    These software supply chain attacks have exposed the underlying weaknesses in the trust model that forms the basis of software delivery in open-source ecosystems, making it one of the most significant and sustained campaigns observed to date. What separates the activity from other incidents is its ability to exponentially propagate across the ecosystem by compromising downstream users and repeating the same cycle.

    “The worm’s genius and the reason conventional defences largely failed is that it operates entirely within legitimate channels. It does not exploit a vulnerability in npm or GitHub,” FalconFeeds.io said. “It exploits the trust model those platforms are built on: the assumption that if a package is signed with a valid key and published by an authenticated maintainer, it is safe.”

    “Shai-Hulud compromises the key and the maintainer, then proceeds to act exactly as a legitimate publisher would. From the registry’s perspective, every malicious publish event is indistinguishable from a routine update.”

    attack Chain GitHub hits major Miasma Microsoft Repositories Supply Worm
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous Article11 ways to make your time feel less rushed during a busy week
    Next Article 82-0 is the best basketball game, to hell with NBA 2K
    admin
    • Website

    Related Posts

    Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

    July 21, 2026

    Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

    July 21, 2026

    WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

    July 21, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Nvidia Wants to Own Every Chip Inside AI Data Centers

    Patek Philippe Debuted the Nautilus 50 Years Ago

    These cities just became America’s hottest buyer’s markets

    The Light Flip Is the Stylish Dumb Flip Phone of Your Dreams

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by