Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
A sophisticated supply chain attack, dubbed Miasma, has compromised 73 Microsoft GitHub repositories, including several within the Azure and Microsoft organizations. The attack leverages a re-compromised PyPI package, durabletask, to spread malicious code, exploiting the trust model of open-source software delivery. This incident highlights vulnerabilities in software supply chains and the potential for attackers to propagate malware through legitimate channels.
The Miasma worm, a variant of the Mini Shai-Hulud worm, has systematically infiltrated Microsoft GitHub repositories, impacting key components of the Azure and Microsoft ecosystems. The initial infection stemmed from the re-compromise of the durabletask PyPI package, which then propagated across a network of related repositories, including implementations in .NET, Go, Java, JS, and MSSQL. GitHub responded by disabling access to the affected repositories following a violation of their terms of service. The attack’s success demonstrates a sophisticated understanding of the open-source software supply chain and the potential for attackers to exploit trust relationships.
