Microsoft GitHub repos hit through trusted maintainer paths
The blast radius is bigger than one infected repo. This worm appears to move through trusted maintainer relationships and shared open-source workflows, so a single compromised access path can reach sibling projects across an organization instead of dying in one repository.
GitHub disabled access to 73 Microsoft repositories across four orgs: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. Reporting also ties the latest wave to a re-compromised Durable Task path, with sibling repos in that ecosystem swept up after the earlier infection.
That makes repo-level trust the control point to watch. If maintainer access, package publishing, or automation can write to multiple projects, one stolen credential or workflow can spread across the rest of the org and keep contaminating adjacent code paths.