For the 2nd time in weeks, Microsoft packages laced with credential stealer

For the 2nd time in weeks, Microsoft packages laced with credential stealer

In a troubling development for Microsoft, several open-source packages were found compromised late last week, harboring sophisticated code designed to steal credentials. This alarming discovery came after automated systems on GitHub flagged 73 packages as malicious, prompting the platform to take action. However, instead of issuing a clear warning about the potential risks, GitHub merely cited a violation of its terms of service, urging package owners to reach out for assistance. It wasn't until the following Monday that Microsoft acknowledged the seriousness of the situation, stating, "We have temporarily removed some repositories as we investigate potential malicious content." This incident marks the second such attack within the past two months, following a breach documented by the firm StepSecurity in May, which compromised the durabletask Python SDK on PyPI. The durabletask package, a framework essential for automating distributed transactions, boasts around 400,000 downloads each month. The malicious packages executed a payload of 28 KB specifically designed to extract credentials from various platforms including AWS, Azure, GCP, and Kubernetes, in addition to numerous developer tool configurations. This malware, dubbed Miasma, has been linked to a threat group known as TeamPCP, which managed to infiltrate Microsoft’s publishing credentials, thereby circumventing the usual safeguards of the repository's build pipeline. Cloudsmith, a security firm, reported that the malware captures OIDC (OpenID-Connect) token credentials, which are instrumental in SLSA (Supply-chain Levels for Software Artifacts) provenance attestation. This method provides cryptographic assurances regarding the integrity of software. Similar to the previous compromise of the durabletask package, last week’s incident also utilized the functionality to pilfer legitimate Microsoft OIDC tokens, which were additionally exploited in a separate attack affecting numerous Red Hat packages.

Sources : Ars Technica

Published On : Jun 08, 2026, 18:40

Space
SpaceX Successfully Tests Starship Rocket, Launching New Era of Space Exploration

On Friday evening, SpaceX executed a significant milestone by launching its colossal Starship rocket from its facility i...

CNBC | Jul 25, 2026, 24:10
SpaceX Successfully Tests Starship Rocket, Launching New Era of Space Exploration
Startups
The Boring Company Eyes $4 Billion Funding Boost Amid Expanding Tunnel Ventures

Elon Musk's tunneling enterprise, The Boring Company, is reportedly negotiating a substantial funding round of $4 billio...

TechCrunch | Jul 25, 2026, 19:50
The Boring Company Eyes $4 Billion Funding Boost Amid Expanding Tunnel Ventures
AI
Revolutionizing Office Automation: Prentis Aims to Secure $100 Million in Funding

Prentis, a newly established AI research lab, is making waves in the tech industry as it prepares to raise $100 million ...

TechCrunch | Jul 25, 2026, 24:00
Revolutionizing Office Automation: Prentis Aims to Secure $100 Million in Funding
Computing
Market Turbulence: Four Key Factors Impacting Stocks This Week

This past week has been challenging for the stock market, driven by several significant forces that have created turbule...

CNBC | Jul 25, 2026, 20:05
Market Turbulence: Four Key Factors Impacting Stocks This Week
Science
Vision Breakthrough: US Startup Launches Groundbreaking Retina Chip in Europe

Science Corp is poised to introduce a revolutionary retina chip in Europe, designed to restore partial vision for indivi...

Business Today | Jul 25, 2026, 01:00
Vision Breakthrough: US Startup Launches Groundbreaking Retina Chip in Europe
View All News