Microsoft disables more than 70 GitHub repositories after hackers compromise them with dangerous malware


  • Threat actor reused unpivoted GitHub stock secrets to compromise 73 Microsoft repositories
  • The Miasma worm is implemented in Azure, Microsoft, Azure-Samples and MicrosoftDocs organizations
  • Microsoft has removed the affected repositories, notified affected customers, and is continuing to investigate

GitHub disabled 73 of Microsoft’s repositories after a malicious actor allegedly used stolen credentials a month ago to break in and install an information stealer.

The news was confirmed by security firm Cloudsmith and malware analysis community site OpenSourceMalware, who revealed that in mid-May 2026, someone (most likely TeamPCP) used stolen Microsoft GitHub Actions secrets to release malicious PyPI packages. Although these were quickly removed from the platform, it appears that Microsoft never disclosed the secrets used in this attack.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top