Threats · 97 days ago
The blast radius is bigger than one infected repo. This worm appears to move through trusted maintainer relationships and shared open-source workflows, so a single compromised access path can reach sibling projects across an organization instead of dying in one repository.
GitHub disabled access to 73 Microsoft repositories across four orgs: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. Reporting also ties the latest wave to a re-compromised Durable Task path, with sibling repos in that ecosystem swept up after the earlier infection.
That makes repo-level trust the control point to watch. If maintainer access, package publishing, or automation can write to multiple projects, one stolen credential or workflow can spread across the rest of the org and keep contaminating adjacent code paths.
3 sources covering this story
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
The attacks stemmed from a GitHub account that was also compromised in a previous Miasma attack on Microsoft last month.
GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections
Miasma worm shapeshifts, but cloud secret-scouting remains the goal
Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
Miasma hit 73 Microsoft repos across four GitHub orgs, forcing access disablement and exposing open-source trust risks.
Part of the PlainSec briefing for 2026-06-10