AUTO-UPDATED

Mantine-datatable (and others) compromised – owner account suspended

A malicious software worm identified as Miasma has compromised 73 Microsoft repositories and various third-party projects, prompting urgent security concerns regarding ongoing supply chain vulnerabilities on GitHub.

Key Points

  • Security researchers identified the Miasma worm, a strain of the Shai-Hulud malware family, targeting software repositories via stolen contributor tokens.
  • The campaign successfully breached 73 Microsoft-owned repositories, including Azure and MicrosoftDocs, before GitHub disabled the affected accounts.
  • Independent analysis by SafeDep confirmed the malicious payload is a byte-level match for the Miasma strain across multiple compromised projects.
  • Developer Ionut Florescu remains locked out of his account, leaving malicious commits active in his repositories despite ongoing efforts to contact GitHub support.
  • Technical documentation and indicators of compromise have been published to assist developers in identifying and mitigating potential infections.

Why it Matters

This incident highlights the significant risks posed by supply chain attacks that leverage stolen authentication tokens to inject malicious code into widely used software repositories. The persistence of the payload in smaller projects underscores the challenges developers face when account suspensions prevent them from removing compromised code.
Github.com Published by icflorescu
Read original