Dispatch
Hackers Plant Credential-Stealing 'Miasma' Malware in Microsoft's Open-Source GitHub Repos
Microsoft and GitHub disabled 70+ Microsoft open-source repositories — many of them Azure and AI developer tools — after attackers injected self-replicating 'Miasma' malware that steals credentials the instant a repo is opened in AI coding tools like Claude Code, Gemini CLI, or VS Code. Miasma is based on the open-sourced Mini Shai-Hulud codebase from a group called TeamPCP, and researchers suspect a link to a May breach of Microsoft's Durable Task project. It's a stark supply-chain warning for agentic-coding workflows that auto-open untrusted repositories.
Source
↳ Follow the thread