StepSecurity
aidefend-sf0031
Miasma 利用儲存庫設定啟動憑證竊取程式
- 自主式 agent
- AI 供應鏈
- 憑證與身分竊取
- 系統入侵與遠端程式碼執行
Miasma 是 StepSecurity 對這起儲存庫供應鏈攻擊使用的名稱。攻擊者透過遭入侵的貢獻者帳號,把 Commit 5f456b8 推送到 Azure/durabletask(Microsoft 的開源 Durable Task 儲存庫);開發者開啟儲存庫時,Claude Code、Gemini CLI、Cursor 或 VS Code 的專案內設定,都可能啟動 4.6 MB、經混淆的憑證竊取程式 .github/setup.js。
對應的威脅技術
AML.T0010.001AI Supply Chain Compromise: AI SoftwareAML.T0011User ExecutionAML.T0051.001LLM Prompt Injection: IndirectAML.T0050Command and Scripting InterpreterAML.T0055Unsecured Credentials