June 5, 2026 — The Miasma worm campaign reached Microsoft’s Azure GitHub organizations. GitHub disabled 73 repositories across Azure, Azure-Samples, Microsoft, and MicrosoftDocs after a malicious commit (5f456b8) was pushed to Azure/durabletask using a previously compromised contributor account.

The attack planted configuration files that execute a credential-harvesting payload when a developer opens the repository in Claude Code, Gemini CLI, Cursor, or VS Code. GitHub disabled affected repos in a 105-second automated sweep. All verified via GitHub API returning HTTP 403 with "reason": "tos".

This extends the June 1 Red Hat npm Miasma campaign. The same contributor account was reused from a prior durabletask breach. Notable impacted repos include durabletask implementations, functions-container-action, llm-fine-tuning, and windows-driver-docs.