GitHub disables Microsoft repos pushing password-stealing malware
Microsoft repositories on GitHub were temporarily disabled on June 5th due to concerns about distributing malware, specifically linked to the ongoing Miasma/Shai-Hulud supply-chain campaign. The incident involved the compromise of several Azure repositories, disrupting workflows and causing confusion for developers. While the repositories have since been restored, the situation highlights vulnerabilities within open-source ecosystems and the need for robust supply chain security measures.
On June 5th, Microsoft took swift action to remove 73 repositories across its GitHub organizations following reports of potential malicious content. This disruption stemmed from a supply-chain attack utilizing the Miasma/Shai-Hulud campaign, which initially targeted Red Hat's npm packages and subsequently pivoted to Microsoft's GitHub resources. The core issue involved a compromised ‘durabletask’ repository, allowing attackers to inject a minimal workflow designed to steal GitHub OIDC tokens. This action impacted workflows like ‘Azure/functions-action,’ causing widespread outages and confusion among developers reliant on these tools. Microsoft attributed the action to an internal management issue and is currently investigating the full extent of the compromise.