RC RANDOM CHAOS

Microsoft pulls 70+ GitHub repos after attackers plant credential stealers

· via Hacker News

Original source

Microsoft's open source tools were hacked to steal passwords of AI developers

Hacker News →

Microsoft has disabled more than 70 of its open source GitHub repositories after attackers compromised the projects and injected malware designed to harvest passwords and credentials from developers. Many of the tainted repos were tied to Azure or to integrations with AI coding assistants like Claude Code, Gemini CLI, and VS Code, meaning the malicious code executed inside the workflows of engineers who often hold keys to cloud infrastructure and production data. Cloudsmith and OpenSourceMalware flagged the intrusion; Microsoft confirmed it notified a small set of customers known to have pulled the affected content but has not disclosed download counts.

The incident is being characterized as a re-compromise of Microsoft’s Durable Task project, which was breached in mid-May, raising the possibility that the original intruders were never fully evicted or that a fresh foothold was established through the same weak link. Either reading is bad for Microsoft, which owns GitHub and is far better resourced than the solo maintainers who are the usual targets of these campaigns.

The attack fits a sharpening pattern of supply chain operations that prize developer-adjacent code as a force multiplier — one poisoned dependency can reach thousands of downstream environments with privileged access. That a vendor of Microsoft’s scale was hit twice in weeks suggests attackers see AI tooling ecosystems as a soft, high-value target worth sustained investment.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.