Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A self-replicating supply chain worm called Miasma has compromised 73 GitHub repositories, including a Microsoft-maintained Azure SDK (durabletask versions 1.4.1-1.4.3), and poisoned 19 PyPI packages with 37 malicious Python wheel artifacts. The attack targets developer environments directly, stealing cloud credentials, API keys, and secrets when developers open affected repositories in AI coding assistants such as Claude Code, Gemini CLI, Cursor, or VS Code and interact with the code via prompt injection. Any organization using the affected Azure SDK versions or the poisoned PyPI packages may have exposed cloud infrastructure credentials, creating immediate risk of unauthorized cloud access, data exfiltration, and lateral movement across production environments.

Author

Tech Jacks Solutions