Microsoft's GitHub Repositories: A Target for Password-Stealing Malware (2026)

GitHub's swift action to disable Microsoft's repositories, which were distributing malware, highlights the ongoing battle against supply-chain attacks in the open-source community. This incident, which occurred on June 5th, was contained within just 105 seconds, demonstrating the importance of rapid response in cybersecurity. The repositories were removed due to concerns that they distributed 'potential malicious content', and multiple researchers confirmed that the repos were pulled after a compromise during a Miasma/Shai-Hulud supply-chain campaign. The 'durabletask' repository, in particular, was compromised in May, indicating that an incomplete cleanup allowed the threat actor to return with a new compromise. This incident has raised concerns about the security of open-source ecosystems and the potential for supply-chain attacks to target AI coding tools. The OpenSourceMalware platform notes that the 'durabletask' package on the Python Package Index (PyPI) had been compromised in May when the threat actor pushed three malicious versions (1.4.1, 1.4.2, 1.4.3). The immediate effect of this incident was disabling access to 'Azure/functions-action', a GitHub Action used by many developers to deploy Azure Functions. Workflows referencing it stopped working, causing an outage and confusion. However, all repositories have been restored and are considered clean and safe to use. Microsoft has also notified a small number of customers who may have pulled down content from the affected repositories. The incident appears to be part of the Miasma malware campaign that infected 32 of Red Hat's npm packages. The hacker pivoted from Red Hat's npm packages to Microsoft's resources on GitHub, targeting AI coding tools such as Claude Code, Gemini CLI, VS Code, and Cursor. This incident highlights the need for software developers to consider locking their project dependencies, adding multi-day time delays to fetch new package updates, and testing new builds on isolated environments. Security teams should also log and alert on more successful attacks to prevent further breaches. The Picus whitepaper provides insights into breach and attack simulation tests that can help identify and stop threats before they cause significant damage.

Microsoft's GitHub Repositories: A Target for Password-Stealing Malware (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Rev. Porsche Oberbrunner

Last Updated:

Views: 6411

Rating: 4.2 / 5 (73 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Rev. Porsche Oberbrunner

Birthday: 1994-06-25

Address: Suite 153 582 Lubowitz Walks, Port Alfredoborough, IN 72879-2838

Phone: +128413562823324

Job: IT Strategist

Hobby: Video gaming, Basketball, Web surfing, Book restoration, Jogging, Shooting, Fishing

Introduction: My name is Rev. Porsche Oberbrunner, I am a zany, graceful, talented, witty, determined, shiny, enchanting person who loves writing and wants to share my knowledge and understanding with you.