Skip to main content
🔥 Controversy⭐ Top story~ Likely74June 9, 2026

Miasma Worm Hits 73 Microsoft GitHub Repos, Steals 2,400 Secrets

Self-replicating Miasma worm compromised 73 Microsoft GitHub repositories, exfiltrating over 2,400 developer credentials via AI coding tools.

China's $295 Billion AI Buildout Locks Out Nvidia, Backs HuaweiMoonshot AI Targets $30B Valuation With Fresh $2B Raise
Insta's take

"Hackers hid malware inside AI coding tool config files and robbed 2,400 secrets from Microsoft's own GitHub. Your dev environment is the new attack surface — act accordingly."

On June 8–9, 2026, Microsoft temporarily disabled dozens of GitHub repositories after the Miasma supply chain worm infected 73 repos across four organizations — Azure, Azure-Samples, Microsoft, and MicrosoftDocs. The attack exploited previously compromised contributor credentials to push a malicious commit to the Azure/durabletask repository, embedding a credential-harvesting payload inside configuration files designed to trigger when opened in AI coding tools including Claude Code, Gemini CLI, and VS Code. GitHub's automated systems disabled the affected repositories in a sweep lasting just 105 seconds.

Miasma is assessed as a variant of the Mini Shai-Hulud worm first observed in mid-May 2026. The same compromised contributor account was linked to a prior May attack on the durabletask PyPI package. The worm exfiltrated over 2,400 secrets and has now infected 113+ repositories across dozens of accounts. Threat group TeamPCP, believed responsible, previously targeted TanStack (CVE-2026-45321, CVSS 9.6), Mistral AI, LiteLLM, Checkmarx, and hundreds of npm packages.

This attack signals a dangerous new frontier: AI developer tooling is now an active attack surface. Malicious hooks embedded in IDE configuration files represent a stealthy, high-yield vector that security teams have largely underestimated until now.

Why Insta thinks this matters

Any team using Microsoft Azure SDKs, VS Code extensions, or AI coding assistants like Claude Code or Gemini CLI may have been exposed to credential-harvesting malware. Enterprises should immediately audit developer environment configurations and rotate cloud credentials. This attack pattern — weaponizing AI tool hooks — is replicable and likely to accelerate.

China's $295 Billion AI Buildout Locks Out Nvidia, Backs HuaweiMoonshot AI Targets $30B Valuation With Fresh $2B Raise
Sources
TechCrunchThe Hacker News404 MediaMicrosoft Security BlogStepSecurity

Relevant tools

Claude
Anthropic's AI assistant known for being thoughtful, safe, a...
StackScore Tools™92
Durable
AI website builder that creates a complete business website ...
StackScore Tools™57
Gemini
Google's flagship multimodal AI assistant for chat, reasonin...
StackScore Tools™86
Mistral
European open-weight AI lab; Le Chat assistant and efficient...
StackScore Tools™81
Pi
Inflection's empathetic personal AI focused on supportive, c...
StackScore Tools™39
Insta's Weekly Digest — every Sunday
Insta Tool Finder

Find the right AI tool for your business

Chat with Insta and get matched to the right tool in seconds.

Try Insta Tool Finder →