June 5, 2026 — The Miasma worm compromised 73 Microsoft GitHub repositories across Azure, Azure-Samples, Microsoft, and MicrosoftDocs. Attack executed using previously compromised contributor credentials to push malicious commit to Azure/durabletask.

Configuration files trigger credential-harvesting payload when repository opened in AI coding tools (Claude Code, Gemini CLI, Cursor, VS Code). The Bun-based worm harvests credentials for AWS, Azure, GCP, Kubernetes, npm, and GitHub, then propagates to additional repositories.

GitHub disabled affected repositories June 5, 16:00:50–16:02:35 UTC in two automated waves over 105 seconds. CI/CD pipelines disrupted, particularly those relying on Azure/functions-action.

Timeline: June 3 second wave of Miasma dead-drop repos; June 5 malicious commit to durabletask; June 5 GitHub takedown sweep.