The Miasma Worm: How AI Coding Agents Became a Supply Chain Attack Surface (opens in new tab)
Microsoft just had 73 GitHub repositories — including the Azure Functions Action — disabled after a supply chain attack that didn't target developers directly. It targeted their AI coding agents. The Miasma worm is a new class of threat. Understanding how it propagated, and why existing defenses missed it, matters for anyone running agentic CI/CD workflows today. What Happened The Miasma worm executed a supply chain attack specifically targeting AI coding agents operating inside CI/CD environ...
Read the original article