Miasma supply-chain compromise disrupts Microsoft GitHub repositories
Case score 69
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 69
- Main story score
- 68
- Related evidence lift
- +1 / 20
- Contributing updates
- 1
- Context updates
- 0
- Incident Direct Microsoft-facing incident with repository removal, CI/CD disruption, and customer notification. main
- Campaign Provides the broader Miasma campaign thread that explains why 73 Microsoft repositories were affected. main
- Campaign Adds directly related June expansion into PyPI and concrete delivery-method details for the ongoing operation. contributes
Overview
Latest development Open development history GitHub removes 73 Microsoft repositories amid suspected Miasma/Shai-Hulud compromise GitHub removed 73 Microsoft repositories across the Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on June 5 after concerns about potential malicious content linked to a Miasma/Shai-Hulud supply-chain campaign. The removal disrupted continuous integration pipelines and broke Azure/functions-action workflows used to deploy Azure Functions.
-
Microsoft restores affected GitHub repositories and notifies customers
Microsoft later restored the affected repositories and said it had notified a small number of customers who may have pulled down content from those repositories. The company said it had temporarily removed some repositories while investigating potential malicious content and would continue to investigate any further customer action needed.
-
Miasma supply-chain campaign expands to 23 more PyPI packages
Microsoft temporarily removed some GitHub repositories after 73 open-source projects were compromised to inject an information stealer, while the broader Miasma, Mini Shai-Hulud, and Hades activity also spread into a new PyPI wave that added 23 packages. The campaign uses multiple delivery methods, including executable .pth startup hooks, trojanized .abi3.so extensions, and a loader that searches sys.path for _index.js, and the payloads target developer workstations and CI/CD environments to harvest secrets and exfiltrate them to a public GitHub repository.