June 5, 2026 — A self-replicating Miasma worm compromised 73 Microsoft GitHub repositories across Azure and related organizations. The attack reused credentials from a prior durabletask breach, injected AI coding agent triggers, and exfiltrated secrets to attacker-controlled repos.
GitHub disabled access within hours. Visitors see Terms of Service violation notices. The campaign follows a Red Hat npm attack that hit 32 packages on June 1.
Microsoft had not issued a detailed public statement as of June 6. Security teams advise: rotate exposed tokens, audit organizations for unexpected public repos, search commit histories for indicators like “firedalazer”, pin GitHub Actions to specific commit SHAs, rebuild CI/CD from clean sources.
Malware samples excluded Step Security domains from Docker setups to evade detection.