Microsoft warns of malicious npm packages and Miasma worm targeting developer supply chain
Microsoft has identified two npm packages that embed a remote‑access trojan capable of harvesting cryptocurrency wallet data, credentials from more than 15 browsers, and developer authentication tokens. The stolen information is exfiltrated by disguising traffic as normal AI‑development requests to popular AI‑platform repositories.
A separate incident involves the self‑replicating Miasma worm, which infected 73 Microsoft‑owned GitHub repositories, including those for Azure and AI development tools. The worm drops a payload into environments such as Claude Code, Gemini CLI, Cursor and VS Code and attempts to steal cloud access keys for AWS, Azure, GCP, npm and GitHub. Administrators disabled the affected repositories within minutes, but the worm can spread autonomously using compromised credentials. Both attacks illustrate growing risks in the open‑source software supply chain and the need for stricter security reviews.