Microsoft disables over 70 GitHub repos after hackers compromised them with dangerous malware


  • Threat actor reused unrooted GitHub Actions secrets to compromise 73 Microsoft repos
  • Miasma worm planted across Azure, Microsoft, Azure-Samples and MicrosoftDocs organizations
  • Microsoft pulled affected repos, notified affected customers and is continuing the investigation

GitHub has disabled 73 of Microsoft’s repositories after a threat actor allegedly used credentials stolen a month ago to break in and plant an info stealer.

The news was confirmed by security firm Cloudsmith and community-run malware analysis site OpenSourceMalware, which revealed that in mid-May 2026, someone (most likely TeamPCP) used stolen Microsoft’s GitHub Actions secrets to release malicious PyPI packages. Although these were quickly pulled from the platform, it appears that Microsoft never rotted the secrets used in this attack.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top