Threat · curated 27 Jun 2026
Miasma Supply Chain Attack: Azure Hit, 73 Repos Down, 37 PyPI Wheels
First reported · updated · 2 reports stepsecurity.io
Coverage timeline
Why it matters
The Miasma campaign weaponizes AI coding agents as an execution surface—payloads fire automatically when a poisoned repository is opened in Claude Code, Cursor, or VS Code—turning developer AI tooling into a credential-exfiltration vector across the software supply chain.
The Miasma supply-chain worm campaign expanded to poison Microsoft's Azure/durabletask GitHub repository with config files that execute a credential-harvesting payload the moment a developer opens the repo in AI coding tools like Claude Code, Gemini CLI, Cursor, or VS Code, triggering GitHub to disable 73 Microsoft repositories including Azure/functions-action. Two days later the Hades variant dropped 37 malicious PyPI wheels across 19 packages using Python .pth startup hooks to run a Bun-powered credential stealer on every interpreter launch, with Socket tracking 448 affected artifacts across npm and PyPI.