Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Miasma Worm Affects 73 Microsoft GitHub Repositories

Miasma Worm Affects 73 Microsoft GitHub Repositories

Posted on June 6, 2026 By CWS

Microsoft has faced a significant security challenge as the Miasma worm has targeted its GitHub repositories. This attack, part of a larger self-replicating supply chain campaign, has disrupted 73 repositories across four Microsoft GitHub organizations, including Azure and MicrosoftDocs, as reported by OpenSourceMalware. The breach has led GitHub to restrict access to these repositories, citing a breach of its terms of service.

Impact on Microsoft Repositories

The repositories affected include notable ones such as Azure and MicrosoftDocs, with the Azure/azure-functions-host being specifically highlighted by GitHub as inaccessible due to policy violations. Some repositories impacted include ‘azure-search-openai-demo-purviewdatasecurity’ and ‘durabletask’ among others. This incident underscores the vulnerability of even major tech giants to cybersecurity threats.

Re-Compromise of the Durabletask Package

A critical aspect of this attack is the re-compromise of the ‘durabletask’ PyPI package, initially breached by TeamPCP to deploy an information-stealing malware on Linux systems. According to security researcher Paul McCarty, the attack extended across multiple related repositories, highlighting a recurring security lapse that suggests incomplete credential revocation from previous incidents.

Evolution of the Miasma Worm

The Miasma worm is believed to be an evolved form of the Mini Shai-Hulud worm, first released by TeamPCP in mid-May 2026. This worm has adapted its tactics, creating new repositories under misleading names such as ‘Miasma: The Spreading Blight’ and ‘Hades – The End for the Damned.’ This adaptability has allowed it to evade traditional defenses and continue spreading across the GitHub ecosystem.

In addition to targeting GitHub repositories, the Miasma worm bypasses npm registry checks, embedding malicious code directly into several repositories such as ‘icflorescu/mantine-datatable.’ By exploiting the trust placed in legitimate software distribution channels, the worm effectively undermines the open-source software supply chain.

Implications for Software Security

The Miasma worm attack highlights fundamental weaknesses in the trust model of open-source software distribution. Unlike typical attacks that exploit vulnerabilities, Miasma leverages the inherent trust in signed and authenticated packages, making it difficult to detect. As FalconFeeds.io notes, the worm operates within legitimate channels, blurring the lines between authentic and malicious activities.

This incident serves as a stark reminder of the vulnerabilities in our software supply chains and the need for robust security measures. As the tech industry continues to grapple with these challenges, improving trust models and enhancing security protocols remain critical priorities.

The Hacker News Tags:Azure, GitHub attack, malicious code, Malware, Miasma worm, Microsoft GitHub, Mini Shai-Hulud, open source security, repository security, security breach, software delivery, software vulnerabilities, supply chain attack, TeamPCP, trust model

Post navigation

Previous Post: Opal Security Secures $23M to Enhance AI Identity Governance

Related Posts

North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware The Hacker News
Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHub Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHub The Hacker News
New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector The Hacker News
SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers The Hacker News
GitHub Breach Linked to Malicious VS Code Extension GitHub Breach Linked to Malicious VS Code Extension The Hacker News
How Passwork 7 Addresses Complexity of Enterprise Security How Passwork 7 Addresses Complexity of Enterprise Security The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Miasma Worm Affects 73 Microsoft GitHub Repositories
  • Opal Security Secures $23M to Enhance AI Identity Governance
  • CISA Flags SolarWinds Vulnerability in Security Alert
  • Hugging Face Vulnerability Risks Remote Code Attacks
  • Smart TVs Used as AI Data Proxies by Free Apps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Miasma Worm Affects 73 Microsoft GitHub Repositories
  • Opal Security Secures $23M to Enhance AI Identity Governance
  • CISA Flags SolarWinds Vulnerability in Security Alert
  • Hugging Face Vulnerability Risks Remote Code Attacks
  • Smart TVs Used as AI Data Proxies by Free Apps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark