Last Updated: 2026-06-08T20:48:52Z
What’s Happening
It appears Microsoft is disabling repositories using Azure DevOps Functions.
This appears to be the attack vector:
Microsoft is now reporting it has informed “a small number” of customers that they may have downloaded infected repos.
Actions
Check if any of your repositories used these tools.
You may also want to search your repos for "Miasma: The Spreading Blight", the string being used by attackers on compromised repos.
Notes
First report here:
Durable Task was compromised on PyPi in May, so this is a repeat.
5 Likes
The source code for the attack has been posted on GitHub.
1 Like