Miasma / Shai-Hulud Supply-Chain Campaign Pushes Password-Stealing Malware via Compromised Microsoft GitHub Repos (durabletask PyPI 1.4.1-1.4.3) — Threadlinqs Intelligence
As of 2026-06-09, Miasma / Shai-Hulud Supply-Chain Campaign Pushes Password-Stealing Malware via Compromised Microsoft GitHub Repos (durabletask PyPI 1.4.1-1.4.3) is a high-severity supply chain threat attributed to Shai-Hulud worm operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-0733 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: Shai-Hulud worm operators · FINANCIAL
On June 5, 2026, GitHub disabled 73 repositories across Microsoft's Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations after they were abused to push password-stealing malware as part of
The June 5, 2026 disablement of 73 Microsoft-owned GitHub repositories is the latest wave of the Shai-Hulud self-replicating supply-chain worm (also tracked under the 'Miasma' and 'IronWorm'/'Mini Shai-Hulud' labels), a campaign that has repeatedly backdoored the npm and PyPI ecosystems since September 2025. In this wave, threat actors compromised a Red Hat employee's GitHub account and used it to pivot into Microsoft's Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations. They injected a minimal malicious GitHub Actions workflow that requested GitHub's OIDC tokens, enabling token theft and onward access. The compromise of the 'durabletask' project in May 2026 produced three malicious PyPI releases (1.4.1, 1.4.2, 1.4.3), and the 'Azure/functions-action' GitHub Action was disabled during remediation, causing deployment-workflow outages for downstream consumers.
The broader Shai-Hulud worm operates by injecting a 'preinstall' script into compromised package.json files together with two payload files, setup_bun.js (a loader that installs the Bun runtime from bun.sh/install) and bun_environment.js (a >10 MB heavily obfuscated credential stealer). Execution during the pre-install phase (rather than post-install) removes the need for human interaction and widens impact across developer workstations and CI/CD pipelines. Using the embedded TruffleHog binary and bespoke enumeration, the malware harvests credentials from the local filesystem and from cloud environments — AWS (IMDSv2, ECS metadata, SSO tokens, credential files), Google Cloud, Azure, Kubernetes, HashiCorp Vault, SSH keys, npm tokens (.npmrc), GitHub Personal Access Tokens, and crypto wallets — writing them to staging files named cloud.json, contents.json, environment.json, and truffleSecrets.json.
Stolen secrets are exfiltrated by creating public GitHub repositories (repo names matching the pattern [0-9a-z]{18}) carrying fixed descriptions such as 'Sha1-Hulud: The Second Coming' and 'Sha1-Hulud: The Continued Coming'. The worm self-propagates: using a stolen npm token it authenticates as the victim developer, enumerates that developer's other packages, injects the payload, and republishes them, spreading exponentially without operator intervention. For persistence and remote execution it registers compromised hosts as self-hosted GitHub Actions runners named SHA1HULUD and commits a malicious workflow (.github/workflows/discussion.yaml). Some variants impersonate 'Linus Torvalds' as the commit author. If credential theft fails, certain variants attempt to destroy the victim's home directory via secure overwriting, marking a shift from espionage toward sabotage. The November 24, 2025 (Shai-Hulud 2.0) wave alone backdoored roughly 700-796 unique npm packages (>20M weekly downloads) and created 25,000+ malicious repositories across ~500 GitHub users, while the May 2026 'Mini Shai-Hulud' resurgence affected 170+ npm packages and 2 PyPI packages. Microsoft Defender detects components as Trojan:JS/ShaiWorm and Behavior:Win32/SuspBunActivity.A.
Weaknesses (CWE)
CWE-506, CWE-1357, CWE-829, CWE-522, CWE-798
Target sectors: technology, software-development, cloud-services, open-source
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1195, T1078, T1586, T1608, T1059, T1059, T1098, T1543, T1027, T1656