A malicious software worm identified as Miasma has compromised 73 Microsoft repositories and various third-party projects, prompting urgent security concerns regarding ongoing supply chain vulnerabilities on GitHub.
Key Points
- Security researchers identified the Miasma worm, a strain of the Shai-Hulud malware family, targeting software repositories via stolen contributor tokens.
- The campaign successfully breached 73 Microsoft-owned repositories, including Azure and MicrosoftDocs, before GitHub disabled the affected accounts.
- Independent analysis by SafeDep confirmed the malicious payload is a byte-level match for the Miasma strain across multiple compromised projects.
- Developer Ionut Florescu remains locked out of his account, leaving malicious commits active in his repositories despite ongoing efforts to contact GitHub support.
- Technical documentation and indicators of compromise have been published to assist developers in identifying and mitigating potential infections.