The Wire.Tracking threats to Agents 312 raw → 45 curated · updated 27 Jun 2026

Incident · curated 27 Jun 2026

Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents - StepSecurity

First reported 8 Jun 2026 · 18d ago

Coverage timeline

8 Jun 2026

Single-source incident — first reported, latest, and curated coincide.

This shows a self-propagating supply-chain worm weaponizing AI coding agents to harvest credentials, turning developer copilots into an attack vector inside trusted repositories.

On June 5, 2026, the Miasma worm campaign pushed a malicious commit to Microsoft's Azure/durabletask repository via a compromised contributor account, planting configuration files that execute a credential-harvesting payload when developers open the repo in AI coding agents like Claude Code, Gemini CLI, Cursor, or VS Code. GitHub disabled 73 repositories across four Microsoft organizations in response.

Why it matters

This shows a self-propagating supply-chain worm weaponizing AI coding agents to harvest credentials, turning developer copilots into an attack vector inside trusted repositories.

Curated from sources around the web.
Permalinks stay valid even if an incident is later merged.   Feed · Search · API docs · RSS