SafeDep reports that a Miasma worm variant injected a large dropper into GitHub repositories across multiple maintainers, using Claude Code, Gemini, Cursor, and VS Code configuration files so the payload can trigger when a cloned repository is opened in an AI coding agent.
Miasma Worm Targets AI Coding Agents via GitHub Repos
SafeDep reports that a Miasma worm variant injected a large dropper into GitHub repositories across multiple maintainers, using Claude Code, Gemini, Cursor, and VS Code configuration files so the payload can trigger when a cloned repository is opened in an AI coding agent.
Source: Safedep