According to the Beating Monitor, over 70 open-source code repositories hosted by Microsoft on GitHub have been swiftly shut down due to a Miasma worm attack. The infected repositories mainly include the Azure Functions host process, as well as the Durable Task task orchestration framework in open-source versions across .NET, Java, Go, and JavaScript, among other languages.
This incident of poisoning at Microsoft is linked to the case of GitHub's internal code theft in mid-May. At that time, the hacking group TeamPCP uploaded a malicious VS Code extension to the Microsoft App Store. Within a mere 11-minute window of availability, a GitHub employee fell victim to the download, leading to the theft of all credentials and keys on the compromised computer. Leveraging these credentials, hackers bypassed security measures and made off with around 3800 internal GitHub repositories. Subsequently, TeamPCP publicly disclosed and open-sourced the self-replicating worm framework Mini Shai-Hulud. The Miasma worm that infiltrated Microsoft this time is an upgraded variant of Mini Shai-Hulud.
The Miasma worm operates with a mechanism specifically targeting AI programming scenarios. Hackers utilized previously stolen Microsoft contributor Tokens to inject malicious code into trusted official repositories. Developers who open or analyze these contaminated projects in AI assistants like Claude Code, Cursor, or Gemini CLI trigger the malicious payload when the programming assistant parses configuration files. Once activated, the worm performs background reconnaissance, stealing developers' AWS, GCP, and Azure cloud credentials, SSH keys, npm/PyPI tokens, and Kubernetes keys. It then uses the newly acquired credentials to search for the next GitHub repository to poison, achieving automated self-replication.
This marks the second compromise of the Microsoft Durable Task open-source project in a matter of weeks (malicious Python dependencies were planted at the end of May). In response to the malicious commits in early June, GitHub's automatic defense system reacted swiftly, automatically shutting down 73 infected repositories within 105 seconds of the code submission, successfully halting the worm's spread. Currently, Microsoft has notified a small number of developers who pulled the compromised code, initiating an urgent credential rotation process and gradually restoring the affected repositories following a security audit. Security agencies advise that as supply chain attacks evolve into automated worms targeting AI agent workflows, developers must prudently assess the risk of running unknown repositories directly in AI assistants.

