Miasma self-replicating supply chain attack campaign targeting open-source repositories
Campaign
Summary
Hide ▲
Show ▼
The Miasma self-replicating supply-chain campaign has reached 73 Microsoft repositories across Azure, Azure-Samples, Microsoft, and MicrosoftDocs on GitHub. GitHub disabled access to the affected repositories on June 5 after concerns about potential malicious content, and the action briefly disrupted workflows tied to Azure/functions-action. Microsoft later restored the repositories and said it had notified a small number of customers who may have pulled affected content. The activity remains linked to TeamPCP and to prior compromise activity involving durabletask and related open-source packages.
Cases
Related Happenings
Cursor Windows repo-root git.exe code execution security flaw
Vulnerability
H score9
First: 15.07.2026 13:55
Last: 15.07.2026 13:55
Sources 1
About this happening:
Cursor on Windows automatically runs a repo-root git.exe when a repository is opened, creating arbitrary code execution as the logged-in user. The flaw affects cloned...
Cursor Windows repo-root git.exe code execution security flaw
VulnerabilityAbout this happening: Cursor on Windows automatically runs a repo-root git.exe when a repository is opened, creating arbitrary code execution as the logged-in user. The flaw affects cloned...
AsyncAPI repositories and npm publishing workflow hit by network compromise
Incident
H score27
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
AsyncAPI repositories and npm publishing workflow hit by network compromise
IncidentAbout this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
GitHub fake-repository infostealer campaign
Campaign
H score41
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...
GitHub fake-repository infostealer campaign
CampaignAbout this happening: A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...
Single organization's private GitHub repository cloned after confirmed access
Data Leak
H score12
First: 09.07.2026 21:38
Last: 09.07.2026 21:38
Sources 1
About this happening:
Confirmed access to a private GitHub repository belonging to one organization marks a concrete data exposure and raises the risk of source-code or internal-content...
Single organization's private GitHub repository cloned after confirmed access
Data LeakAbout this happening: Confirmed access to a private GitHub repository belonging to one organization marks a concrete data exposure and raises the risk of source-code or internal-content...
GitHub API enumeration campaign targeting corporate organizations
Campaign
H score17
First: 09.07.2026 21:38
Last: 09.07.2026 21:38
Sources 1
About this happening:
A GitHub API reconnaissance campaign is systematically mapping corporate organizations, repositories, and user accounts across multiple companies, expanding the risk of fo...
GitHub API enumeration campaign targeting corporate organizations
CampaignAbout this happening: A GitHub API reconnaissance campaign is systematically mapping corporate organizations, repositories, and user accounts across multiple companies, expanding the risk of fo...
Timeline
-
06.06.2026 09:58 4 articles · 1mo ago
Miasma campaign hits 73 Microsoft GitHub repositories
Initial DisclosureThe ongoing Miasma self-replicating supply-chain campaign affects 73 Microsoft repositories across Azure, Azure-Samples, Microsoft, and MicrosoftDocs, and GitHub disables access to the compromised repositories after a terms-of-service violation is detected on Azure/azure-functions-host.
Show sources
- Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack — thehackernews.com — 06.06.2026 09:58
- Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack — thehackernews.com — 06.06.2026 09:58
- GitHub disables Microsoft repos pushing password-stealing malware — www.bleepingcomputer.com — 09.06.2026 18:42
- The ‘Miasma’ worm source code briefly leaked on GitHub — www.bleepingcomputer.com — 10.06.2026 23:27