Miasma worm is a self‑replicating supply‑chain malware campaign and Mitigation
The Miasma worm is a self‑replicating supply‑chain malware campaign that struck 73 Microsoft GitHub repositories across four major Microsoft organizations — Azure, Azure‑Samples, Microsoft, and MicrosoftDocs — in early June 2026. It represents one of the most significant escalations in modern software‑supply‑chain attacks, especially because it targets AI‑assisted developer tools rather than traditional package‑install mechanisms. What Happened A malicious commit was pushed into the Azure/durabletask repository using previously compromised contributor credentials . GitHub responded by disabling 73 Microsoft repositories in an automated sweep lasting 105 seconds . The commit did not modify source code. Instead, it added configuration files designed to auto‑execute a 4.3–4.6 MB obfuscated JavaScript payload when opened in: Claude Code Gemini CLI Cursor Visual Studio Code npm test script Why This Attack Is Different Traditional supply‑chain attacks rely on poisoning package re...