StepSecurity
aidefend-sf0031
Miasma Repository Settings Trigger Credential Harvester
- Autonomous Agents
- AI Supply Chain
- Credential & Identity Theft
- System Compromise & RCE
A compromised contributor account pushed commit 5f456b8 to Azure/durabletask. When a developer opens the repository, Claude Code or Gemini CLI SessionStart hooks, a Cursor always-applied rule, or a VS Code folder-open task can launch .github/setup.js, a 4.6 MB obfuscated credential harvester.
Mapped threat techniques
AML.T0010.001AI Supply Chain Compromise: AI SoftwareAML.T0011User ExecutionAML.T0051.001LLM Prompt Injection: IndirectAML.T0050Command and Scripting InterpreterAML.T0055Unsecured Credentials