Rogue Agent Watch › Records › miasma-worm-ai-coding-agent-configs
Miasma worm: Azure/durabletask commit weaponized AI coding-agent configuration files; 73 Microsoft repositories disabled
Disclosed · added to the index · last updated
Grades
- Verification status
- Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Significant — AI materially enabled or accelerated the operation, but was one of several important components.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
On 2026-06-05 StepSecurity reported that a malicious commit pushed to the Azure/durabletask repository through a previously compromised contributor account added configuration and hook files for Claude Code, Gemini CLI, Cursor and VS Code, so that a developer opening the repository in those tools triggered credential harvesting. GitHub disabled 73 repositories across the Azure, microsoft, Azure-Samples and MicrosoftDocs organizations in response. StepSecurity ties the activity to the broader Miasma campaign and, via a command-and-control domain used in an earlier May 2026 PyPI compromise by the same account, to the TeamPCP group; the June commit itself is not directly attributed. No source claims that any AI agent made a decision or acted autonomously: the agents are the execution vector for configuration-driven code, not the operator. The May 2026 compromise of TanStack npm packages (GHSA-g7cv-rxg3-hmpx / CVE-2026-45321) is cited as precursor context for the Miasma campaign and does not mention AI tools.
Impact as stated
Per StepSecurity: credential harvesting from developer systems that opened the affected repository in Claude Code, Gemini CLI, Cursor or VS Code; 73 repositories disabled by GitHub across the Azure, microsoft, Azure-Samples and MicrosoftDocs organizations. No victim count is stated.
Facts as stated by sources
- Actor
- TeamPCP (per StepSecurity, via command-and-control infrastructure linked to the same account's earlier PyPI attack; the June commit is not directly attributed) (Cybercriminal)
- Category
- Infrastructure abuse / supply chain
- Models named
- not named by sources
- Model families
- Claude (Anthropic), Gemini (Google), Other / unspecified
- Agentic autonomy level
- Not applicable
- Guardrail bypass
- Indirect prompt injection, Legitimate tool abuse
- Attack lifecycle phases
- Initial access, Execution, Credential access, Exfiltration
- Target sectors
- Technology
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
Mitigations as stated
- StepSecurity recommends required pull-request review with no direct pushes to protected branches, OIDC trusted publishing instead of long-lived tokens, pinning Actions to commit SHAs, restricted outbound CI network access, monitoring for releases lacking matching tags or CI runs, treating editor and AI-agent configuration files as supply-chain signals, and rotating credentials on any system that opened an affected repository.
- GitHub disabled 73 affected repositories across four Microsoft-owned organizations.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
- Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools
- Amazon Q Developer VS Code extension compromise (data-wiping prompt injection)
- Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm release
Sources (2)
- Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents
StepSecurity · Vendor report · · archived copy - Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys (GHSA-g7cv-rxg3-hmpx)
GitHub Advisory Database · Other · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "miasma-worm-ai-coding-agent-configs". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/miasma-worm-ai-coding-agent-configs.json — CC BY-SA 4.0.