Rogue Agent Watch › Records › miasma-worm-ai-coding-agent-configs

Miasma worm: Azure/durabletask commit weaponized AI coding-agent configuration files; 73 Microsoft repositories disabled

Disclosed · added to the index · last updated

Grades

Verification status
Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Significant — AI materially enabled or accelerated the operation, but was one of several important components.
Severity
High — Significant confirmed harm to one or more organizations.

Summary

On 2026-06-05 StepSecurity reported that a malicious commit pushed to the Azure/durabletask repository through a previously compromised contributor account added configuration and hook files for Claude Code, Gemini CLI, Cursor and VS Code, so that a developer opening the repository in those tools triggered credential harvesting. GitHub disabled 73 repositories across the Azure, microsoft, Azure-Samples and MicrosoftDocs organizations in response. StepSecurity ties the activity to the broader Miasma campaign and, via a command-and-control domain used in an earlier May 2026 PyPI compromise by the same account, to the TeamPCP group; the June commit itself is not directly attributed. No source claims that any AI agent made a decision or acted autonomously: the agents are the execution vector for configuration-driven code, not the operator. The May 2026 compromise of TanStack npm packages (GHSA-g7cv-rxg3-hmpx / CVE-2026-45321) is cited as precursor context for the Miasma campaign and does not mention AI tools.

Impact as stated

Per StepSecurity: credential harvesting from developer systems that opened the affected repository in Claude Code, Gemini CLI, Cursor or VS Code; 73 repositories disabled by GitHub across the Azure, microsoft, Azure-Samples and MicrosoftDocs organizations. No victim count is stated.

Facts as stated by sources

Actor
TeamPCP (per StepSecurity, via command-and-control infrastructure linked to the same account's earlier PyPI attack; the June commit is not directly attributed) (Cybercriminal)
Category
Infrastructure abuse / supply chain
Models named
not named by sources
Model families
Claude (Anthropic), Gemini (Google), Other / unspecified
Agentic autonomy level
Not applicable
Guardrail bypass
Indirect prompt injection, Legitimate tool abuse
Attack lifecycle phases
Initial access, Execution, Credential access, Exfiltration
Target sectors
Technology
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

CVE
CVE-2026-45321

Mitigations as stated

  • StepSecurity recommends required pull-request review with no direct pushes to protected branches, OIDC trusted publishing instead of long-lived tokens, pinning Actions to commit SHAs, restricted outbound CI network access, monitoring for releases lacking matching tags or CI runs, treating editor and AI-agent configuration files as supply-chain signals, and rotating credentials on any system that opened an affected repository.
  • GitHub disabled 73 affected repositories across four Microsoft-owned organizations.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (2)

  1. Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents
    StepSecurity · Vendor report · · archived copy
  2. Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys (GHSA-g7cv-rxg3-hmpx)
    GitHub Advisory Database · Other · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "miasma-worm-ai-coding-agent-configs". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/miasma-worm-ai-coding-agent-configs.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction