GitHub Removes 73 Microsoft Repos After Miasma Malware Attack
GitHub temporarily disabled 73 Microsoft repositories on June 5 2026 after detecting the Miasma (also called Shai‑Hulud) worm, which had been introduced through a compromised employee account. The malicious commit added configuration files that enabled remote code execution when the repos were opened in AI‑assisted development tools such as Claude Code, Gemini CLI and Cursor.
The removal, which lasted about 105 seconds, caused immediate interruptions in CI/CD pipelines that rely on the affected projects, notably the Azure/functions‑action used for Azure Functions deployments. The incident highlights the risk of supply‑chain attacks that exploit valid credentials and trusted integrations, a threat first traced to the npm ecosystem and a Red Hat‑related component before moving laterally into Microsoft’s Azure tooling.
Developers worldwide were prompted with temporary access restrictions, and the event underscored the broader vulnerability of cloud‑based development workflows to sophisticated credential‑theft campaigns.