Seventy-three Microsoft open source packages were compromised late last week with malware that steals credentials from cloud services and developer tools. The malicious code activates when opened in AI coding agents.
Automated systems on GitHub blocked the packages after detecting the threat. GitHub disabled them citing a terms of service violation rather than labeling them malicious. Microsoft sent an email on Monday stating it had temporarily removed some repositories while investigating potential malicious content. This marks the second such incident involving a Microsoft account in recent months. The malware, known as Miasma, uses a 28-kilobyte payload linked to threat actor TeamPCP. It targets credentials for AWS, Azure, GCP, Kubernetes, and password managers before spreading laterally. The same GitHub account was used in a May compromise of the DurableTask Python SDK. Security researchers noted the attack bypasses traditional detection by generating unique encrypted payloads for each infection.