Microsoft disables over 70 GitHub repos after hackers compromised them with dangerous malware

https://cdn.mos.cms.futurecdn.net/2viAsX89eJReYQEQ3i3SwH-750-80.jpg
  • Threat actor reused unrotated GitHub Actions secrets to compromise 73 Microsoft repos
  • Miasma worm planted across Azure, microsoft, Azure‑Samples, and MicrosoftDocs orgs
  • Microsoft pulled affected repos, notified impacted customers, and continues investigation

GitHub has disabled 73 of Microsoft’s repositories after a threat actor allegedly used credentials stolen a month ago to break in and plant an infostealer.

The news was confirmed by security firm Cloudsmith and community-driven malware analysis site OpenSourceMalware, which revealed that in mid-May 2026, someone (most likely TeamPCP) used stolen Microsoft’s GitHub Actions secrets to publish malicious PyPI packages. While these were quickly yanked from the platform, it seems that Microsoft never rotated the secrets used in this attack.

Now, it would appear that the same threat actor used the same credentials to compromise 73 new repositories, spanning four GitHub organizations: Azure, Azure-Samples, microsoft, and MicrosoftDocs. The Azure org bore the brunt, losing 49...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE