Opening SecureFlowMiasma Repository Settings Trigger Credential Harvester
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

StepSecurity aidefend-sf0031

Miasma Repository Settings Trigger Credential Harvester

  • Autonomous Agents
  • AI Supply Chain
  • Credential & Identity Theft
  • System Compromise & RCE

A compromised contributor account pushed commit 5f456b8 to Azure/durabletask. When a developer opens the repository, Claude Code or Gemini CLI SessionStart hooks, a Cursor always-applied rule, or a VS Code folder-open task can launch .github/setup.js, a 4.6 MB obfuscated credential harvester.

Mapped threat techniques

  • AML.T0010.001 AI Supply Chain Compromise: AI Software
  • AML.T0011 User Execution
  • AML.T0051.001 LLM Prompt Injection: Indirect
  • AML.T0050 Command and Scripting Interpreter
  • AML.T0055 Unsecured Credentials

Source