According to monitoring by Beating, Microsoft's 73 open-source repositories on GitHub were automatically shut down on June 9 after being poisoned by the Miasma worm. The infected projects primarily included Azure Functions host processes and Durable Task orchestration framework versions across .NET, Java, Go, and JavaScript.
Microsoft disclosed that this attack originates from the same threat actor behind the May mid-month GitHub internal code breach. In that incident, hackers from TeamPCP uploaded a malicious VS Code extension to Microsoft's marketplace, compromising a GitHub employee's credentials within an 11-minute window. The breached credentials allowed attackers to steal approximately 3,800 internal GitHub repositories and subsequently release a self-replicating worm framework called Mini Shai-Hulud. The current Miasma worm is an upgraded variant of Mini Shai-Hulud, specifically engineered to target AI-assisted coding workflows.