# Microsoft Disables 73 GitHub Repositories After Supply-Chain Malware Campaign Targets AI Development Tools


Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs GitHub organizations on June 5, 2026, following the discovery of password-stealing malware distributed through a sophisticated supply-chain attack. The incident, which was contained within 105 seconds, represents the latest escalation in ongoing efforts by threat actors to compromise development tools and infrastructure targeting artificial intelligence coding platforms.


The attack has been attributed to the Miasma/Shai-Hulud campaign, a coordinated malware operation that has recently expanded its scope from Red Hat's npm package ecosystem to high-profile Microsoft repositories, raising critical questions about the security of open-source dependencies and continuous integration pipelines across the tech industry.


## The Incident: Scope and Timeline


On June 5, GitHub Staff disabled 73 repositories spanning multiple Microsoft GitHub organizations without advance notice. The rapid response—with the incident contained in just 105 seconds—demonstrates automated detection systems working as intended, but the brief window of exposure was enough to cause significant disruption to development workflows across the industry.


The repositories included critical developer tools, particularly Azure/functions-action, a widely-used GitHub Action that enables developers to deploy Azure Functions directly from their CI/CD pipelines. The sudden removal of this action caused immediate outages for organizations whose workflows depended on it, with build processes failing due to missing action references.


Key timeline of events:

  • May 2026: The 'durabletask' repository compromised; malicious versions pushed to PyPI
  • June 5, 2026: 73 Microsoft repositories disabled; incident contained within 105 seconds
  • June 5-6, 2026: All repositories restored after Microsoft investigation
  • June 8-9, 2026: Additional Shai-Hulud attacks detected, including compromise of Pythagora-io/gpt-pilot (33,700+ GitHub stars)

  • ## Background and Context: The Miasma Campaign


    The June 5 incident is not an isolated attack but rather the latest manifestation of the broader Miasma/Shai-Hulud supply-chain campaign, which has been systematically targeting the open-source development ecosystem since late 2025. According to security researchers at Cloudsmith, the threat actors behind Miasma have specifically focused on AI-powered coding tools and assistants—including Claude Code, Gemini CLI, VS Code extensions, and Cursor.


    The campaign's sophistication lies in its targeted approach: rather than broadly distributing malware, threat actors have identified high-value supply chains and developer tooling that would compromise large numbers of downstream users if poisoned.


    Previous Miasma operations included:

  • Compromise of 32 npm packages in the @redhat-cloud-services namespace
  • Initial attack vector: compromised Red Hat employee's GitHub account
  • Malicious workflow injection requesting GitHub OIDC (OpenID Connect) tokens
  • Lateral movement from Red Hat infrastructure to Microsoft repositories

  • ## Technical Details: How the Attack Worked


    The Miasma campaign demonstrates a sophisticated understanding of modern CI/CD infrastructure and GitHub's authentication mechanisms. The attack chain reveals a multi-stage progression:


    ### Initial Compromise

    Threat actors gained access to a Red Hat employee's GitHub credentials, allowing them to push commits to internal repositories. Rather than uploading obvious malware, attackers injected minimal workflow files—subtle changes that would evade casual code review.


    ### Token Exploitation

    The critical technical innovation in this attack was the exploitation of GitHub OIDC tokens. These tokens are automatically generated and provided to GitHub Actions workflows, allowing automation systems to authenticate with GitHub and other platforms without storing static credentials. By injecting workflows that requested OIDC tokens, threat actors gained the ability to perform authenticated operations against multiple GitHub organizations.


    ### The Malware Payload

    Security analysis confirms that the distributed malware targeted password-stealing functionality, likely designed to harvest credentials from developers' machines or extract secrets from CI/CD environments. The presence of malicious versions (1.4.1, 1.4.2, 1.4.3) of the 'durabletask' package on PyPI indicates the attackers had compromised both the source repository and the downstream package distribution channel.


    ### Target-Specific Delivery

    Unlike indiscriminate malware campaigns, Miasma was engineered to target developers using specific AI-assisted coding tools. This precision suggests threat actors either:

  • Sought to compromise specific high-value targets using these tools
  • Aimed to inject malicious behavior into AI coding assistants themselves
  • Planned to harvest API keys or credentials used by these tools

  • ## Implications: Scope and Risk Assessment


    The Microsoft incident highlights critical vulnerabilities in how the software development ecosystem manages security:


    | Aspect | Risk Level | Impact |

    |--------|-----------|--------|

    | Downstream users | High | Any developer using Azure Functions Action was exposed |

    | Package maintainers | Critical | Credentials and OIDC tokens could be harvested |

    | AI tool users | High | Malware specifically targeted AI-assisted development platforms |

    | CI/CD pipelines | High | Workflow disruption and potential secret exfiltration |


    Who was affected:

  • All organizations using Azure/functions-action for function deployment
  • Developers who pulled durabletask package versions 1.4.1-1.4.3 from PyPI
  • Users of Python projects with durabletask as a dependency
  • Potentially any developer whose credentials were exposed through compromised repositories

  • Microsoft stated that it notified "a small number of customers who may have pulled down content from the affected repositories," though the actual number of impacted developers may be substantially larger given the widespread use of Azure Functions tooling.


    ## Response and Remediation


    Microsoft's response was swift and transparent:


  • Immediate action: Disabled 73 compromised repositories within 105 seconds of detection
  • Investigation: Conducted rapid forensic analysis to confirm malicious content
  • Restoration: Re-enabled all repositories after confirming they contained no malicious code
  • Notification: Reached out to affected customers through established support channels
  • Commitment: Pledged continued investigation and proactive notification of any additional findings

  • A Microsoft spokesperson attributed the incident to "an internal management issue" requiring investigation, while clarifying the repositories were disabled "due to a violation of GitHub's terms of service."


    However, questions remain about how the compromise occurred in the first place and what additional safeguards Microsoft is implementing to prevent recurrence.


    ## Recommendations for Development Teams


    Organizations relying on Microsoft's Azure ecosystem and open-source dependencies should take immediate protective measures:


    Immediate Actions:

  • Audit all workflows and scripts currently using Azure/functions-action and verify they haven't been modified
  • Check deployment logs for any unusual deployments that occurred on or after June 5
  • Review access logs for GitHub OIDC token usage during the affected period
  • Scan systems where durabletask was installed for unauthorized activity

  • Ongoing Protection Strategy:

  • Dependency locking: Pin exact versions of dependencies and avoid automatic updates
  • Time delays: Implement multi-day delays before pulling new package versions into production
  • Isolated testing: Test new builds and dependencies in isolated sandbox environments before production deployment
  • Code review requirements: Enforce multi-reviewer approval for any dependency updates, particularly for AI development tools
  • Secrets rotation: Rotate any credentials or API keys that may have been exposed
  • OIDC monitoring: Monitor OIDC token usage for unusual patterns or unexpected authentication requests

  • ---


    ## HackWire Analysis


    The Miasma campaign represents a fundamental shift in supply-chain attack sophistication. Previous incidents like SolarWinds or the xz-utils backdoor typically involved either direct payload injection or dependency confusion attacks. Miasma differs critically: it doesn't just poison packages—it specifically targets the authentication and orchestration layer of modern development infrastructure through OIDC token exploitation.


    What makes this moment significant is the timing. The campaign targets AI-assisted development tools at the exact moment these tools are becoming integral to enterprise software development. If threat actors successfully compromise Claude Code, Cursor, or VS Code AI extensions at scale, they don't just steal credentials—they potentially inject malicious behavior into millions of developers' daily workflows. An AI tool with malicious instructions could subtly modify generated code in ways that propagate vulnerabilities across an organization's entire codebase.


    The lateral movement from Red Hat to Microsoft reveals another pattern worth recognizing: threat actors are now mapping the interconnected nature of open-source dependencies. Red Hat's npm packages aren't used in isolation—they integrate with Azure, GitHub Actions, and dozens of other downstream systems. One compromised employee's credentials became a pivot point for accessing completely separate infrastructure.


    For defenders, this incident exposes a critical gap: most organizations focus security hardening on the deployment target (production systems, databases, cloud infrastructure) but treat development infrastructure as a secondary concern. GitHub credentials, OIDC tokens, and package registries often have weaker access controls than production systems, yet they control what code actually reaches production. Until security teams invert this hierarchy—treating development infrastructure with the same rigor as production—supply-chain attacks will remain high-probability events.


    The 105-second containment window also offers false reassurance. Yes, Microsoft's automation detected and disabled the repositories quickly. But threat actors had 30+ days (May through June 5) to operate within the 'durabletask' repository before discovery. Supply-chain security isn't measured in seconds of detection speed—it's measured in how long malicious code can operate undetected.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)