Microsoft disables 73 GitHub repositories after Miasma worm supply‑chain attack
A self‑replicating worm dubbed Miasma compromised 73 Microsoft‑owned GitHub repositories, injecting malicious commits that stole cloud credentials from developers and CI/CD systems. The worm leveraged AI coding tools, automatically executing when an infected repository was cloned, and used legitimate OIDC tokens to publish malicious npm packages, making detection difficult. The attack follows a May incident involving the same durabletask PyPI token, raising questions about whether Microsoft fully remediated the earlier breach.
Microsoft temporarily removed the affected repositories, later restoring them after review, and notified a small number of customers who may have pulled down content. While the company has not disclosed how many developers were impacted, the incident highlights systemic weaknesses in software supply‑chain trust infrastructure and the need for stronger anomaly detection in publishing pipelines.