The pervasive malware campaign named Miasma has caused a significant stir in the open-source community, with approximately 73 Microsoft GitHub repositories falling victim to this insidious worm. To mitigate the risk and ascertain the method by which attackers infiltrated projects and inserted password-stealing malware within the code, these repositories were temporarily suspended for investigation.
The affected repositories encompass a wide range of organizations, including Microsoft Azure, Azure-Samples, Microsoft, and MicrosoftDocs. This malware allows attackers to pilfer passwords and credentials when compromised tools are opened in popular AI coding applications such as Claude Code, Gemini CLI, VS Code, and Cursor.
Initial reports of the hack were made by security firms like Cloudsmith, malware analysis site OpenSourceMalware, and 404 Media. It is essential to note that Miasma is a derivative of the Mini Shai-Hulud worm, which was open-sourced by the threat group TeamPCP. The malware’s inception can be traced back to the compromise of a Red Hat employee’s GitHub account for an attack on the @redhat-cloud-services npm namespace.
Earlier this month, Microsoft Threat Intelligence disclosed that the Miasma attackers published 32 malicious packages across over 90 versions under the @redhat-cloud-services npm scope, with the intention of stealing cloud credentials.
The worm swiftly shifted its focus from package registries to directly infiltrating source code repositories. By bypassing the npm registry entirely, it injected malicious code straight into public projects such as icflorescu/mantine-datatable, exploiting the growing reliance on AI‑powered coding assistants.
Once a compromised repository is opened in an AI coding tool or an integrated development environment, the embedded payload can automatically execute, delivering a stealthy attack vector. Notable victims include the durabletask Python package, which had already been targeted a month earlier by TeamPCP with a Linux‑specific information stealer.
In response, Microsoft has begun restoring several repositories that were impacted by the malware campaign, according to The Hacker News. A company spokesperson emphasized the priority of safeguarding both customers and the wider ecosystem, explaining that some repositories were temporarily removed for investigation. After thorough review, many have been reinstated, while others remain offline pending further analysis.
Microsoft is actively probing the recent security breach and has already alerted a handful of customers who may have had to delete content from the compromised repositories. The firm will re‑contact affected users via its established support channels if any additional actions become necessary.
News Source: Neowin
Comments
Be the first to comment.