# Microsoft Disables 73 GitHub Repositories After Supply-Chain Malware Campaign Targets AI Development Tools
Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs GitHub organizations on June 5, 2026, following the discovery of password-stealing malware distributed through a sophisticated supply-chain attack. The incident, which was contained within 105 seconds, represents the latest escalation in ongoing efforts by threat actors to compromise development tools and infrastructure targeting artificial intelligence coding platforms.
The attack has been attributed to the Miasma/Shai-Hulud campaign, a coordinated malware operation that has recently expanded its scope from Red Hat's npm package ecosystem to high-profile Microsoft repositories, raising critical questions about the security of open-source dependencies and continuous integration pipelines across the tech industry.
## The Incident: Scope and Timeline
On June 5, GitHub Staff disabled 73 repositories spanning multiple Microsoft GitHub organizations without advance notice. The rapid response—with the incident contained in just 105 seconds—demonstrates automated detection systems working as intended, but the brief window of exposure was enough to cause significant disruption to development workflows across the industry.
The repositories included critical developer tools, particularly Azure/functions-action, a widely-used GitHub Action that enables developers to deploy Azure Functions directly from their CI/CD pipelines. The sudden removal of this action caused immediate outages for organizations whose workflows depended on it, with build processes failing due to missing action references.
Key timeline of events:
## Background and Context: The Miasma Campaign
The June 5 incident is not an isolated attack but rather the latest manifestation of the broader Miasma/Shai-Hulud supply-chain campaign, which has been systematically targeting the open-source development ecosystem since late 2025. According to security researchers at Cloudsmith, the threat actors behind Miasma have specifically focused on AI-powered coding tools and assistants—including Claude Code, Gemini CLI, VS Code extensions, and Cursor.
The campaign's sophistication lies in its targeted approach: rather than broadly distributing malware, threat actors have identified high-value supply chains and developer tooling that would compromise large numbers of downstream users if poisoned.
Previous Miasma operations included:
## Technical Details: How the Attack Worked
The Miasma campaign demonstrates a sophisticated understanding of modern CI/CD infrastructure and GitHub's authentication mechanisms. The attack chain reveals a multi-stage progression:
### Initial Compromise
Threat actors gained access to a Red Hat employee's GitHub credentials, allowing them to push commits to internal repositories. Rather than uploading obvious malware, attackers injected minimal workflow files—subtle changes that would evade casual code review.
### Token Exploitation
The critical technical innovation in this attack was the exploitation of GitHub OIDC tokens. These tokens are automatically generated and provided to GitHub Actions workflows, allowing automation systems to authenticate with GitHub and other platforms without storing static credentials. By injecting workflows that requested OIDC tokens, threat actors gained the ability to perform authenticated operations against multiple GitHub organizations.
### The Malware Payload
Security analysis confirms that the distributed malware targeted password-stealing functionality, likely designed to harvest credentials from developers' machines or extract secrets from CI/CD environments. The presence of malicious versions (1.4.1, 1.4.2, 1.4.3) of the 'durabletask' package on PyPI indicates the attackers had compromised both the source repository and the downstream package distribution channel.
### Target-Specific Delivery
Unlike indiscriminate malware campaigns, Miasma was engineered to target developers using specific AI-assisted coding tools. This precision suggests threat actors either:
## Implications: Scope and Risk Assessment
The Microsoft incident highlights critical vulnerabilities in how the software development ecosystem manages security:
| Aspect | Risk Level | Impact |
|--------|-----------|--------|
| Downstream users | High | Any developer using Azure Functions Action was exposed |
| Package maintainers | Critical | Credentials and OIDC tokens could be harvested |
| AI tool users | High | Malware specifically targeted AI-assisted development platforms |
| CI/CD pipelines | High | Workflow disruption and potential secret exfiltration |
Who was affected:
Microsoft stated that it notified "a small number of customers who may have pulled down content from the affected repositories," though the actual number of impacted developers may be substantially larger given the widespread use of Azure Functions tooling.
## Response and Remediation
Microsoft's response was swift and transparent:
A Microsoft spokesperson attributed the incident to "an internal management issue" requiring investigation, while clarifying the repositories were disabled "due to a violation of GitHub's terms of service."
However, questions remain about how the compromise occurred in the first place and what additional safeguards Microsoft is implementing to prevent recurrence.
## Recommendations for Development Teams
Organizations relying on Microsoft's Azure ecosystem and open-source dependencies should take immediate protective measures:
Immediate Actions:
Ongoing Protection Strategy:
---
## HackWire Analysis
The Miasma campaign represents a fundamental shift in supply-chain attack sophistication. Previous incidents like SolarWinds or the xz-utils backdoor typically involved either direct payload injection or dependency confusion attacks. Miasma differs critically: it doesn't just poison packages—it specifically targets the authentication and orchestration layer of modern development infrastructure through OIDC token exploitation.
What makes this moment significant is the timing. The campaign targets AI-assisted development tools at the exact moment these tools are becoming integral to enterprise software development. If threat actors successfully compromise Claude Code, Cursor, or VS Code AI extensions at scale, they don't just steal credentials—they potentially inject malicious behavior into millions of developers' daily workflows. An AI tool with malicious instructions could subtly modify generated code in ways that propagate vulnerabilities across an organization's entire codebase.
The lateral movement from Red Hat to Microsoft reveals another pattern worth recognizing: threat actors are now mapping the interconnected nature of open-source dependencies. Red Hat's npm packages aren't used in isolation—they integrate with Azure, GitHub Actions, and dozens of other downstream systems. One compromised employee's credentials became a pivot point for accessing completely separate infrastructure.
For defenders, this incident exposes a critical gap: most organizations focus security hardening on the deployment target (production systems, databases, cloud infrastructure) but treat development infrastructure as a secondary concern. GitHub credentials, OIDC tokens, and package registries often have weaker access controls than production systems, yet they control what code actually reaches production. Until security teams invert this hierarchy—treating development infrastructure with the same rigor as production—supply-chain attacks will remain high-probability events.
The 105-second containment window also offers false reassurance. Yes, Microsoft's automation detected and disabled the repositories quickly. But threat actors had 30+ days (May through June 5) to operate within the 'durabletask' repository before discovery. Supply-chain security isn't measured in seconds of detection speed—it's measured in how long malicious code can operate undetected.
— HackWire Editorial
---
## Related Coverage