Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Addresses GitHub Security Breach Amid Ongoing Probe

Microsoft Addresses GitHub Security Breach Amid Ongoing Probe

Posted on June 9, 2026 By CWS

Microsoft has taken steps to address a recent security breach that impacted several GitHub repositories. On Monday, the tech giant confirmed that it temporarily removed some repositories following the discovery of a security incident where 73 open-source projects were compromised. The breach involved injecting an information-stealing malware into the project code.

Microsoft’s Response to the Breach

A Microsoft representative emphasized the company’s commitment to protecting its users and the broader ecosystem. “We have temporarily taken down certain repositories to investigate potentially harmful content,” the spokesperson explained. While some repositories have been restored after thorough review, others will remain offline as the investigation continues.

Microsoft has also alerted a select group of customers who might have downloaded content from the affected repositories. The company assured that it would continue to monitor the situation and directly contact customers if further actions are necessary.

Details of the Miasma Campaign

This incident is part of a larger software supply chain campaign known as Miasma. Recently, Microsoft restricted access to several open-source projects on GitHub after reports of their compromise. Among the affected projects was “durabletask,” a Python package targeted by the cybercrime group TeamPCP to deploy an information stealer aimed at Linux systems.

Further investigation into the Miasma payload revealed the ability to execute code automatically when developers open the repository using AI-powered coding tools or integrated development environments (IDEs). This is part of a continuous strategy to plant malware in widely used open-source packages, potentially affecting downstream users.

Adapting Threats and Future Outlook

Recent findings indicate that the threat actors are experimenting with new payload delivery methods. Earlier packages used startup hooks to run a JavaScript stealer, but newer variants employ different tactics. These include Trojanized native extensions and modified startup hook loaders, which separate the malware loader from the payload to evade static analysis detection.

Despite the methods employed, the malware’s objective remains the same: targeting developer workstations and CI/CD environments to capture sensitive data and transmit it to a public GitHub repository. A notable aspect of the bioinformatics package is its ability to bypass AI-powered analysis tools through adversarial prompt injections.

Kirill Boychenko, a researcher at Socket, highlighted that the Hades branch of the Miasma campaign exemplifies a rapidly evolving supply chain threat. As these attacks continue to develop, monitoring and safeguarding against such vulnerabilities remain critical for developers and organizations worldwide.

The Hacker News Tags:AI security, Cybersecurity, GitHub, Malware, Miasma, Microsoft, Open Source, security breach, software supply chain, TeamPCP

Post navigation

Previous Post: Microsoft Entra Logs Expose Risky Agent Activities
Next Post: OpenSSL Addresses Critical Vulnerability with AI Assistance

Related Posts

PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain The Hacker News
Google Cloud Vertex AI SDK Flaw Exposed Model Uploads Google Cloud Vertex AI SDK Flaw Exposed Model Uploads The Hacker News
Abandoned Sogou Zhuyin Update Server Hijacked, Weaponized in Taiwan Espionage Campaign Abandoned Sogou Zhuyin Update Server Hijacked, Weaponized in Taiwan Espionage Campaign The Hacker News
Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign The Hacker News
GeoServer Exploits, PolarEdge, and Gayfemboy Push Cybercrime Beyond Traditional Botnets GeoServer Exploits, PolarEdge, and Gayfemboy Push Cybercrime Beyond Traditional Botnets The Hacker News
Chaos Ransomware Uses Headless Browsers for Stealthy Attacks Chaos Ransomware Uses Headless Browsers for Stealthy Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark