The Shai Hulud Supply Chain Worm Just Compromised 73 of Microsoft’s Own GitHub Repositories — The Platform That Hosts the World’s Code Was Distributing Malware From Its Own Azure Namespace

🤚 The Open-Palm Repo Lockdown

The Shai Hulud supply chain worm — a name we have now typed so many times it has its own keyboard shortcut — has reached what can only be described as its prestige phase. On June 5th, GitHub disabled 73 repositories belonging to Microsoft itself after discovering they had been compromised and were actively distributing password-stealing malware.

Let that settle in. Microsoft’s own repositories on Microsoft’s own platform were pushing malware to Microsoft’s own users. The snake has eaten its own tail, and the tail was signed with a valid certificate.

The affected repos spanned four official Microsoft organizations: Azure, microsoft, Azure-Samples, and MicrosoftDocs. The most impactful casualty was “Azure/functions-action,” a GitHub Action used by thousands of developers to deploy Azure Functions — meaning the supply chain attack didn’t just steal credentials, it broke the deployment pipeline when Microsoft pulled the plug. Your CI/CD was compromised, and then it was offline. Choose your adventure.

👐 The Two-Handed Franchise Update

For those keeping score at home — and we have been, with increasing alarm — here is the Shai Hulud cinematic universe timeline:

  • May 13: The original Shai Hulud attack compromises hundreds of signed npm and PyPI packages. Your cryptographic verification verified the malware.
  • June 2: The sequel, dubbed “Miasma,” hits 32 official Red Hat npm packages via the @redhat-cloud-services namespace.
  • June 5: The franchise expands to Microsoft. 73 repos disabled. The durabletask PyPI package had three malicious versions pushed in May — 1.4.1, 1.4.2, and 1.4.3 — meaning the attackers were iterating on their malware like it was a product roadmap.
  • June 9: Public disclosure. The internet finds out.

According to researchers at Cloudsmith, the attack chain began with a compromised Red Hat employee’s GitHub account. From there, the attackers pushed unreviewed orphan commits to internal repositories and injected a minimal workflow that requested GitHub’s OIDC tokens — the authentication mechanism that lets GitHub Actions prove they are who they say they are. Once you have OIDC tokens, you don’t need to break into anything. The front door opens itself.

Researchers from Socket, StepSecurity, and the OpenSourceMalware platform all confirmed the compromise. Microsoft contained the incident within 105 seconds of detection, which is genuinely impressive — although one might note that the malicious packages had been sitting in PyPI since May, so the 105-second response time is doing a lot of heavy lifting against a multi-week dwell time.

🌿 The Gentle Awakening

There is a particular kind of existential vertigo that comes from watching a supply chain attack target the supply chain itself. GitHub Actions are infrastructure. Azure Functions deployments are infrastructure. OIDC tokens are the trust fabric of infrastructure. When the worm compromises these, it isn’t attacking your application — it’s attacking the concept of deploying applications.

The affected tools include Claude Code, Gemini CLI, VS Code, and Cursor — which means the AI coding assistants that are writing an increasing share of the world’s software were themselves targets of the supply chain that delivers software. If your AI agent’s dependencies are compromised, does the AI know? Does it care? Does it just pip install the malware and write you a docstring about it?

The Shai Hulud campaign has now compromised packages across npm, PyPI, Red Hat’s official namespace, and Microsoft’s own GitHub organizations. At this point, it’s not a supply chain attack. It’s a supply chain audit conducted by people who did not ask permission and are keeping the findings.

👑 The Gold-Leaf Trust Deficit

The fundamental problem is not that 73 Microsoft repos were compromised. The fundamental problem is that the trust model of open-source software assumes the publisher is who they say they are, and the Shai Hulud campaign has spent the last month proving, systematically and repeatedly, that this assumption is negotiable.

Code signing didn’t help — the original attack compromised signed packages. Namespace ownership didn’t help — Red Hat’s official npm scope was breached. And now organizational trust didn’t help — Microsoft’s own repos on Microsoft’s own platform distributed malware to Microsoft’s own users.

Every layer of trust that was supposed to prevent this has been individually defeated. Not bypassed. Not exploited through some exotic zero-day. Defeated through social engineering, credential theft, and the quiet insertion of orphan commits that nobody reviewed.

Microsoft’s 105-second containment time is admirable. But the question the industry should be asking is not “how fast can we respond?” It’s “why did a single compromised employee account at Red Hat cascade into 73 disabled repositories at Microsoft?” The answer, of course, is that the supply chain is not a chain at all. It’s a web, and every strand vibrates when you pull one.

The worm is called Shai Hulud — the sandworm from Dune. In the novel, you don’t fight the sandworm. You learn to ride it. The open-source ecosystem is currently in the “getting swallowed” phase of that metaphor.

“The worm compromised Red Hat, then Microsoft, then the tools that write the code that runs on Microsoft. At this point, Shai Hulud doesn’t need a kill chain — it has a franchise agreement and a content calendar.” — The Slap of Wisdom Supply Chain Desk, verifying its own dependencies for the third time today and finding the experience deeply unsatisfying