171 pointsby raffael_de3 hours ago21 comments
  • JdeBP2 hours ago
    These seem related:

    * https://news.ycombinator.com/item?id=48418318 (The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds)

    * https://news.ycombinator.com/item?id=48450543 (Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents)

    * https://news.ycombinator.com/item?id=48416155

    * https://news.ycombinator.com/item?id=48416269 (Miasma Worm Targets AI Coding Agents via GitHub Repos)

  • _pdp_2 hours ago
    What follows next is purely speculation and it is based on my own observations and thoughts but based on what I've seen the old RBAC models, while being almost broken before, now it is fully broken, with the fact that now coding assistants and engineers are working on multiple unrelated projects simultaneously - especially working on wild experiments they had no time for previously. The risk of supply chain issue has increased dramatically in the enterprise.

    Again, I am not saying it is related but I think it has an impact.

    Now in many places it is encouraged by coders and managers to vibe stuff on their own devices. Soon or later it will become a problem, especially for those that have no idea what they are doing.

    I am not saying it is related but I feel that it coincides perfectly.

    I just cannot believe there is no underlaying thread going through all of these recent supply chain issues, and yes there are some hacking groups that specialise in this, sure, but it is because the bounty is plentiful.

    • altairprimean hour ago
      I argued for years that we had too few workers for our total project count and management argued that most projects were idle and so it was fine to have so many per worker.

      Welp.

      • _pdp_an hour ago
        I think web-based IDEs like GitHub Codespaces (but even VSCode with tunnels) is part of the solution because at the very least you can get an isolated dev environment per project. I've been advocating for this for as long as I remember.

        Unfortunately, most developers don't like them so it is a though sell.

        • domh15 minutes ago
          Web-based IDEs like VSCode on github just had a 1-click github token stealing vulnerability: https://blog.ammaraskar.com/github-token-stealing/

          You could argue this is probably on GitHub for creating a token here that gives blanket access to all repos vs a scoped token for just the repo.

        • altairprimean hour ago
          Is the theory here that the browser cannot be co-opted to infect web-based repositories? Also: thinking of how yt-dlp can integrate with browser cookies now and the malware paths that opens up. (This is part of why Chrome wants HSM cookies, I expect: DRM and opsec!)
          • _pdp_36 minutes ago
            In this scenario the malware will not be on the device but in an isolated dev environment on a remote machine. So it will have access to whatever was configured in that repo but hopefully the project is isolated enough to ensure containment and prevent cross-pollination.
    • black_knightan hour ago
      Do you mean that role based access control (RBAC) should be replaced by something else? Or that just the specific RBAC models in use are broken?

      I personally think the, perhaps confusingly named, capability based security models are the way of The Future.

    • sourcecodeplzan hour ago
      one could also vibe-code vanilla, no dependencies.
      • _pdp_an hour ago
        You can vibe code safely for sure.

        I am not saying vibe coding is the issue. The issue is that a typical developer might be working on a lot more projects that run concurrently then they used to. And because of the various nature of the project the risk is significantly increased.

        Scale this across the workforce and you not just doubled the problem.

  • bob10292 hours ago
    I strongly suspect this is a case of classic personal access tokens being used in an unclean way.

    If you are going to be handing tokens to AI agents on weird openclaw contraptions, you should try to use the fine grained variants. My GitHub account spans 3 organizations with wildly differing policies. The fact that classic tokens are even still allowed blows my mind a bit. You should be required to manually opt in each organization at a minimum.

    • trumpdonga minute ago
      I use classic tokens on low-privileged accounts for scraping public repos. I suppose organization level permissions would work fine for me.
    • test20201an hour ago
      You are correct but the issue is permission management with finegrained tokens is nighmare. It is not easy to decide what is correct and what is needed for some operation. Furthermore, often software devs think it is important to focus on code rather than permissions - as it is for someone else's responsibility....
  • protoman30002 hours ago
    And we trust these people with the root CA cert in our Secure Boot?
    • justinclift2 hours ago
      More like "forced to accept" rather than "trust".

      This latest event just continues Microsoft's track record of being a security problem rather than having their shit together. :(

    • shaknaan hour ago
      You mean the company that failed their 2023 security review? [0]

      > Individually, any one of the failings described above might be understandable. Taken together, they point to a failure of Microsoft’s organizational controls and governance, and of its corporate culture around security.

      Microsoft’s products and services are ubiquitous. It is one of the most important technology companies in the world, if not the most important. This position brings with it utmost and global responsibilities. It requires a security-focused corporate culture of accountability, which starts with the CEO, to ensure that financial or other go-to-market factors do not undermine cybersecurity and the protection of Microsoft’s customers.

      > Unfortunately, throughout this review, the Board identified a series of operational and strategic decisions that collectively point to a corporate culture in Microsoft that deprioritized both enterprise security investments and rigorous risk management. These decisions resulted in significant costs and harm for Microsoft customers around the world.

      > The Board is convinced that Microsoft should address its security culture.

      [0] https://www.cisa.gov/resources-tools/resources/CSRB-Review-S...

    • AdamN14 minutes ago
      What do you mean 'we'? :-)
    • sunaookamian hour ago
      No one should be foolish enough to trust Microsoft with anything regarding security. They showed time and time again over the past 40 years that they don't care.
      • trumpdong10 minutes ago
        Have you bought a PC in the last 10 years? Then it came with Microsoft's secure boot keys on it. Sometimes it's not even possible to remove or disable them. Sometimes you actually need a Microsoft-signed bootloader shim to boot anything that isn't Microsoft.
    • 2 hours ago
      undefined
  • ashishban hour ago
    Nobody should do 'npm install' or 'pip install' on their machine.

    Using a proper sandboxing(https://github.com/ashishb/amazing-sandbox) regularly will drastically limit the blast radius of these attacks.

    • pritambaral41 minutes ago
      > https://github.com/ashishb/amazing-sandbox

      Does your Docker backend run commands in rootless containers? I skimmed the code but didn't see anything to confirm this.

    • graemepan hour ago
      > Nobody should do 'npm install' or 'pip install' on their machine.

      What alternative do you suggest?

      Do you mean not install outside a sandbox?

      • themafia28 minutes ago
        Download source. Extract. Move files to correct node_modules folder.

        If your distribution requires more than this, then it's not really a module, or combines too many non-modular components, and should be distributed differently.

        The ability for npm to run scripts on any level should be removed.

        Then we can go back to worrying about namespacing issues.

        • dist-epoch11 minutes ago
          If an attacker can infect the post-install script of an npm package, they can also infect the package source code itself. So if you ever run the project outside the sandbox, you will still get compromised.

          It's like saying "I don't trust a software app with an installer, I just want a .zip with the binaries from the same source that I will run myself"

          • themafia2 minutes ago
            > they can also infect the package source code itself

            Which is where the concept of "safe levels" come in. I should be able to install this module in such a way where file operations and process operations are not available to it. That being said, presumably, this types of infiltration would seem to be _much_ easier to spot. "Why is this web framework calling 'spawn'?"

            > I just want a .zip with the binaries

            I want a .zip with the _code_. Just the code. None of the packaging nonsense. My distribution can handle that.

    • 31 minutes ago
      undefined
  • bilekas2 hours ago
    The phrasing of the title is loaded and the content phrases it as some kind of fault of open source.

    Then, which I find the most amusing, proceeds to blame MicroSlop for the attempted suuply chain attack,

    > Microsoft did not immediately provide the specific number of customers affected, when asked by TechCrunch.

    Yeah, because that's how open source works. Tech crunch doing hard work no not explain that.

    > This is Microsoft’s second known breach over the past few weeks that has allowed hackers to compromise its open source projects, per Ars Technica.

    I, like many others love to knock on Microslop when I can, but in this case they did the right thing. The article phrases it like they did everything wrong, they're all at fault and shame on them for limiting the breach.

    This is not the first time I've seen an article from Zack Whittaker that just rubbed me the wrong way.

    > steal passwords of AI developers

    This phrasing has it's own connotations. AI developers versus developers who use AI?

    > This is the latest example in recent months of hackers breaching widely popular open source projects with the aim of planting malware on a large number of users who have the code installed on their computers. These hacks are known as “supply chain” attacks as they target code that is often used in a large number of software products, or by a specific kind of user, which may be advantageous to hack as they sometimes have access to cloud systems and large amounts of customers’ data.

    Describes literally nothing of what a supply chain attack is, just the result of one and the reasons for their attack surface.

    Very very bad reporting in my opinion. Bad breach, and I hate to admit M$ did the safe and right thing, but this 'reporting' leaves a lot to be desired.

    • dgellow2 hours ago
      TechCrunch is very sloppy and unreliable. I’ve seen them reporting on things I worked on where they just invented facts for SEO purpose and there is no way to get them to correct
    • raffael_de2 hours ago
      What's your post mortem, then? As in - what happened and how should it be read?
      • bilekas2 hours ago
        Microsoft's open source projects the target of a supply chain attack and they decided to restrict access to understand and limit exposure ? Something a little more 'true' and less targetted?
        • philipwhiukan hour ago
          Azure are able to be targets of supply chain attack because of the supply chain ecosystem that they still own. It's not really a supply chain when it's still yours.
          • bilekas30 minutes ago
            > It's not really a supply chain when it's still yours.

            I don't personally buy that, they offer a package manager in the form of nuget for example, if their products there are compromised, they're well withing normal reach to block THEIR packages, but why would they need to block the rest ?

            Maybe I'm missing something dumb

    • philipwhiukan hour ago
      > > This is Microsoft’s second known breach over the past few weeks that has allowed hackers to compromise its open source projects, per Ars Technica.

      > I, like many others love to knock on Microslop when I can, but in this case they did the right thing.

      I've no idea what your problem with this sentence is. They have an organisational security problem, aided/demonstrated by lack of effort to effectively lockdown GitHub Actions and allowing MRs to circumvent CI/CD.

      That this is a Microsoft problem that was present pre-AI is not up for debate. See https://www.cisa.gov/sites/default/files/2025-03/CSRBReviewO...

      In the age of AI, it's now endemic and being weaponised.

  • haute_cuisine42 minutes ago
    Please, someone explain how it's possible to add obfuscated file to so many repositories? Do they don't have any code reviews?

    Also, the title is misleading, setup adds config to be auto executed by people who work on the repo. They would have to use vscode/cursor/claude/gemini. People who use codex / opencode / other harnesses are safe I guess.

    Details: https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-...

    • axegon_21 minutes ago
      > Do they don't have any code reviews?

      I have a good friend that works for one of the giants(I can't say which one for obvious reasons but S&P 500). He's been working there for quite a while now, so far he hasn't seen what the project he works on looks like, has the repo cloned and knows what language is used but nothing beyond that. Everything is slopped together. His project is the authentication and authorization system for all the company products. In his own words "I hit Tab all day long and write 'this is intended', the reviews which are all ai, there is no human in the loop. This is what we are told to do by the CEO and CTO unironically. If something breaks, no one knows how any of this works since no one has seen the actual code. Our performance reviews are based on how many tokens we've used, not what we have done". I suspect this is the case in many companies now so it's not unreasonable to think that there are no actual code reviews.

      • trumpdong9 minutes ago
        the reasons are not obvious. I want to avoid their products.Does anyone else *cough* who has a throwaway account know the place?
        • axegon_4 minutes ago
          At this point, I suspect that is just about every tech company. Your best bet is to self-host everything, no agents, no cloud services, completely locked up home network and a loaded shotgun if anything starts making unexpected noises.
    • vorticalbox34 minutes ago
      if an account with the ability to push to the repo was taken over, there wouldn't be any PR review.
  • zihotki2 hours ago
    And the best recommendation security teams can give - keep your SBOM strict, use min release age policy (sounds more like band-aid). That's a scary world to live in.
    • wolfi12 hours ago
      a friend of mine has a very different solution: he codes everything by hand. he says that the time you need to research to include a new package you can actually use to code the piece you need. and he for sure doesn't have the problems of transitive dependencies
      • niccean hour ago
        Depending of the scenario, it can be very fine. E.g. if you just need one or two function call from the dependency. However, for some complex binary protocols it might be better to stick with libraries.
      • hsbauauvhabzban hour ago
        But now he needs to develop, test and maintain that code. Left pad is easily hand coded, react framework not so much.
        • wolfi137 minutes ago
          his projects were GUIs for machines (HMI)
      • dgellow2 hours ago
        I assume that means he genAIs all his deps? Rather than writing by hand
    • niccean hour ago
      > keep your SBOM strict

      Based on the news, seems like it is better to not include Microsoft at all in there.

  • minraws2 hours ago
    Remember folks Microsoft has Mythos access
    • 2 hours ago
      undefined
  • abc3354an hour ago
    "No way to prevent this" say users of only package manager where this... Oh no sorry I thought this was Javascript Haters weekly meetup
  • axus2 hours ago
    Their source has the list of the 73 disabled repositories: https://opensourcemalware.com/blog/miasma-reaches-azure
    • antiloper2 hours ago
      AI;DR:

      Azure (49)

      azure-functions-agents-runtime azure-functions-connector-extension azure-functions-core-tools azure-functions-docker azure-functions-dotnet-extensions azure-functions-dotnet-worker azure-functions-durable-extension azure-functions-durable-js azure-functions-durable-powershell azure-functions-durable-python azure-functions-extension-bundles azure-functions-golang-worker azure-functions-host azure-functions-java-library azure-functions-java-worker azure-functions-kafka-extension azure-functions-language-worker-protobuf azure-functions-mcp-extension azure-functions-nodejs-e2e-tests azure-functions-nodejs-library azure-functions-nodejs-opentelemetry azure-functions-nodejs-worker azure-functions-openai-extension azure-functions-powershell-library azure-functions-powershell-opentelemetry azure-functions-powershell-worker azure-functions-python-extensions azure-functions-python-library azure-functions-python-worker azure-functions-rabbitmq-extension azure-functions-skills azure-functions-sql-extension azure-functions-templates azure-functions-tooling-feed azure-functions-vs-build-sdk azure-webjobs-sdk azure-webjobs-sdk-extensions azure-websites-security checkaccess-v2-go-sdk Connectors-NET-LSP Connectors-NET-Samples Connectors-NET-SDK Connectors-NodeJS-SDK connectors-python-sdk durabletask functions-action functions-container-action homebrew-functions sonic-gnmi.msft

      microsoft (10)

      DurableFunctionsMonitor durabletask-dotnet durabletask-go durabletask-java durabletask-js durabletask-mssql durabletask-netherite durabletask-protobuf Microsoft-Performance-Tools-Apple secure-azureai-agent

      Azure-Samples (13)

      azure-ai-content-understanding-python azure-container-apps-multi-agent-workflow azure-container-apps-sandboxes azure-functions-java-flex-consumption-azd azure-functions-nodejs-opentelemetry-samples azure-search-openai-demo-purviewdatasecurity functions-connectors-python functions-connectors-typescript llm-fine-tuning openai-chat-app-entra-auth-builtin openai-chat-app-entra-auth-local rag-postgres-openai-python tutor

      MicrosoftDocs (1)

      windows-driver-docs

      • sph42 minutes ago
        There is such a thing as too much software.
        • trumpdong6 minutes ago
          Indeed. Every line of code is like a liability, but managers suddenly decided to stack rank developers based on number of lines of code written, again, which is like ranking aircraft designs by how heavy they are.
  • jbverschoor2 hours ago
    Note that also the homebrew-tap was affected: homebrew-functions
  • raincole2 hours ago
    > steal passwords of AI developers

    What does this even mean?

    The malware specifically steals passwords from developers who use AI? From those who develop AI tool? Or it steals API tokens, which serve a similar function as passwords do for humans?

    Is this what journalism looks like today? Just slap the two holy letters on the title and you get views?

    (Yes, I read the article. No, I still don't think the title makes sense. You can skip this techchurch slop and read the real information here: https://opensourcemalware.com/blog/miasma-reaches-azure)

    • Ukvan hour ago
      https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-... mentions that it plants `.claude/settings.json`, `.gemini/settings.json`, `.cursor/rules/setup.mdc`, and `.vscode/tasks.json` to execute its payload as a setup task.

      VSCode will be used by plenty of non-AI-using developers, and the credential harvester is not specific to AI API tokens, but that 3/4 of the targets are AI coding tools is I assume where the claim comes from.

    • trumpdong5 minutes ago
      > you can skip the slop and read the real information here: (link that is obviously written by AI)
    • sourcecodeplzan hour ago
      Do I remember correctly when techcrunch was charging $10k per month for a square banner on its website, 2005? And that was considered the top, for a tech blog. Even then they posted slop.
  • shevy-java25 minutes ago
    GitHub keeps on having problems a LOT in the last months.

    Skynet is winning now.

  • yossufyahiaan hour ago
    It actually feels like nothing is safe now every day you hear about hacking is it from the ai making development weak or ai is getting strong in hacking
    • Zolomonan hour ago
      It was never safe to begin with, that is why the security community has been screaming for resources since the 80s.
  • dude2507112 hours ago
    The Age of Agentic Development.
    • sph39 minutes ago
      I haven’t worked on any web app in months, I don’t use LLMs, I update my Linux system once a month, and I increasingly feel I should just not do anything, not install or update any software and for the love of God, do not touch anything that’s shipped with npm.

      Most of my userspace apps are in Flatpak sandboxes (yeah they are not great), but otherwise it feels like isolation and airgapping is the most sensible solution for now, and it’ll get increasingly worse unless the vibe coders somehow learn how to write robust software.

      It’s like during the black plague: the (software) world has become dangerous, we have no way to contain it, it is unfeasible to remove yourself completely from the world, so you better pray really hard you don’t catch the bug and infect your peers. How’s that for a field we used to call software engineering or computer science?

  • axegon_2 hours ago
    I hate to be the "I told you" guy but... I told you and have been for years. And every time I do, a flock of sloppers come to say "but have you tried the claude sloppus, it's so good man, I haven't written any code in X months". Well.. Enjoy.
  • TZubiri2 hours ago
    another day, another supply chain vulnerability
  • ares6232 hours ago
    guys. what the fuck. are we even doing.
    • nDRDY2 hours ago
      We are ever-faster approaching the Anti Singularity, the moment when everything "tech" implodes and progress screeches to a halt.
      • narrator2 hours ago
        What if this is "The Great Filter?" [Ominous music plays in the background]
        • natebc15 minutes ago
          We've got a few candidates for that on the go and this is for sure one of them.
    • christophilus2 hours ago
      Downloading OpenBSD and going off-grid. How about you?
    • larodi2 hours ago
      getting deeper and deeper. the question is what goes one when breaches reach opensource-based stuff running nuclear reactors. i'd be concerned.
  • verminator468an hour ago
    [dead]
  • Lapsa2 hours ago
    [dead]