Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A self-replicating worm designated Miasma has compromised 73 Microsoft GitHub repositories across the Azure, Azure-Samples, Microsoft, and MicrosoftDocs organizations by exploiting stolen publisher credentials. The attack vector exploits stolen publisher credentials, meaning malicious commits pass standard integrity checks and appear to originate from authorized maintainer accounts. The worm targets the Azure Durable Task ecosystem and propagates downstream through PyPI and npm package registries, meaning any organization consuming these packages in production pipelines may have ingested compromised code. A secondary payload component specifically targets AI-assisted coding environments (Claude Code, Gemini CLI, Cursor, VS Code), meaning developers who clone affected repositories in these environments may trigger autonomous payload execution on their local workstations, extending the blast radius into enterprise development environments.

Author

Tech Jacks Solutions