More than 70 Microsoft open-source libraries were infected by the Miasma worm, and the worm was part of the same group that emptied GitHub in May.
According to Beating's monitoring, over 70 open-source code repositories hosted by Microsoft on GitHub were urgently shut down due to a Miasma worm attack. The infected repositories primarily included Azure Functions host processes and open-source versions of the Durable Task orchestration framework in multiple languages, including .NET, Java, Go, and JavaScript. This attack on Microsoft is linked to the internal GitHub code theft in mid-May. At that time, the hacker group TeamPCP released an infected VS Code extension on the Microsoft Store. A GitHub employee downloaded and became infected during the brief 11-minute upload window, resulting in the theft of all credentials and keys from their computer. The hackers used these credentials to bypass the security network and steal approximately 3,800 internal GitHub repositories. After the success, TeamPCP publicly released and open-sourced the self-replicating worm framework Mini Shai-Hulud on their forums. The Miasma worm that infiltrated Microsoft is a variant and upgraded version of Mini Shai-Hulud. The Miasma worm's operating mechanism is specifically designed for AI programming scenarios. Hackers use previously stolen Microsoft contributor tokens to inject malicious code into trusted official repositories. Developers only need to open or analyze these infected projects in AI assistants such as Claude Code, Cursor, or Gemini CLI, and the programming assistant will automatically trigger the malicious payload when parsing the configuration file. Once activated, the worm scans disks in the background, stealing AWS, GCP, and Azure cloud credentials, as well as SSH keys, npm/PyPI tokens, and Kubernetes keys from the developer's computer. It then uses the newly acquired credentials to find the next GitHub repository to infect, achieving automated self-replication. This is the second time in a few weeks that the Microsoft Durable Task open-source project has been compromised (it was previously injected with a malicious Python dependency package at the end of May). In response to the malicious commit in early June, GitHub's automated defense system reacted extremely quickly, automatically shutting down 73 infected repositories within 105 seconds of the code submission, successfully stopping the worm's spread. Microsoft has notified a small number of developers who pulled the compromised code to begin emergency credential rotation and to gradually restore the affected repositories following a security audit. Security agencies warn that as supply chain attacks evolve into automated worms targeting AI agent workflows, developers must carefully assess the risks of running unknown repositories directly within AI assistants.
免责声明:以上内容仅为作者观点,不代表 711BTC 的任何立场,不构成与 711BTC 相关的任何投资建议。