## Author: Marcus Webb

- 10th June 2026

## [Miasma Worm Reaches Microsoft Azure and PyPI: 73 Repositories Disabled, Hades Wave Drops 37 Malicious Python Wheels](/content/miasma-azure-hades-pypi-supply-chain-worm-2026/index.html)

The Miasma worm crossed two new boundaries in 48 hours: GitHub’s automated enforcement disabled 73 Microsoft repositories in 105 seconds after AI coding agent hooks were planted in Azure/durabletask, then 37 malicious PyPI wheels hit 19 packages with .pth startup hooks that steal credentials on every Python invocation. 448 total artifacts tracked. Zero CVEs assigned across the entire campaign.

## [Vulnerapocalypse — From Vulnerability Discovery to Remediation Speed: Surviving the AI-Driven Patch Wave](/content/vulnerapocalypse-ai-patch-wave-remediation-speed/index.html)

AI now generates working exploits in 10–15 minutes. Verizon’s DBIR confirms software vulnerabilities have overtaken stolen credentials as the top breach entry point. The NCSC and Bank of England have formally demanded automated, at-scale remediation. This analysis breaks down why traditional vulnerability management is broken, what the 2026 supply-chain attack catalogue tells us, and how to close the tap and burn down the backlog before the patch wave hits.

## [TeamPCP Wave Four: GitHub Breach via Poisoned VS Code Extension, durabletask PyPI Worm, and ~4,000 Internal Repositories Exfiltrated](/content/teampcp-github-breach-durabletask-pypi-supply-chain-wave-four-2026/index.html)

TeamPCP’s Mini Shai-Hulud worm hit GitHub and PyPI simultaneously on May 19–20, 2026. Three backdoored versions of durabletask — Microsoft’s Azure Python SDK with 417,000 monthly downloads — were published and yanked within hours. A poisoned VS Code extension on a GitHub employee device led to the exfiltration of ~3,800 internal repositories, now listed for sale at $50,000. Zero CVEs exist across the entire nine-week campaign. Traditional scanners have no record of any of it.

## [TeamPCP / Mini Shai-Hulud npm Campaign: 600 Packages, Confirmed Active Payload, Memory Scraping, and 2,500+ Compromised GitHub Repositories](/content/teampcp-mini-shai-hulud-npm-atool-maintainer-compromise-2026/index.html)

TeamPCP compromised npm maintainer atool across 323 packages. Confirmed payload scrapes CI/CD secrets from Runner.Worker memory, exfiltrates via fake OTel C2. Zero CVEs.
