Microsoft’s open source tools were hacked to steal passwords of AI developers

Microsoft’s open source tools were hacked to steal passwords of AI developers

Microsoft has temporarily suspended access to numerous open-source projects on GitHub as it looks into a security breach that led to the injection of password-stealing malware into its code. Many of the compromised projects are associated with Microsoft's Azure cloud services and tools utilized by developers in AI programming applications, including Claude Code, Gemini's command line interface, and Visual Studio Code. According to cybersecurity experts from Cloudsmith and the community-driven site OpenSourceMalware, the malware enabled hackers to capture users' passwords and other sensitive information when developers interacted with the compromised tools. The exact number of users who have downloaded the affected software remains unclear. Microsoft has confirmed the removal of these repositories, as initially reported by 404 Media. A spokesperson acknowledged receiving inquiries but did not provide further comments at the moment. Currently, at least 70 of Microsoft's projects have been marked as “disabled” on GitHub, displaying a message indicating a violation of GitHub's terms of service. This incident is part of a troubling trend where hackers exploit popular open-source projects to deploy malware, targeting a wide range of users who might have the code installed on their systems. Such attacks are referred to as “supply chain” attacks, focusing on software that is commonly used in various products or by specific user groups, which can often include access to sensitive cloud systems and customer data. While smaller open-source projects frequently fall victim to such attacks, it is less common for large corporations like Microsoft, which usually possess the resources to safeguard against these threats, to experience such breaches. This marks Microsoft's second known incident in recent weeks involving the compromise of its open-source projects. Earlier in May, security researchers reported a hack of Microsoft's Durable Task project, which aids developers in app creation. OpenSourceMalware has indicated that the recent breach may be a “re-compromise” of the Durable Task project, raising concerns that previous security measures may not have fully eliminated the threat or that a new breach has occurred entirely.

Sources : TechCrunch

Published On : Jun 08, 2026, 20:35

Automotive
Ford Teams Up with Apple to Revolutionize Electric Vehicle Technology

Apple has unveiled a suite of developer tools designed to allow car manufacturers to integrate Apple Maps directly into ...

TechCrunch | Jul 23, 2026, 14:05
Ford Teams Up with Apple to Revolutionize Electric Vehicle Technology
Mobile
iPhone 17 Series Price Surge Expected in India: Up to ₹12,000 Increase

Apple is reportedly planning to raise prices for the iPhone 17 series in India, mirroring recent price hikes in Japan. S...

Business Today | Jul 23, 2026, 10:10
iPhone 17 Series Price Surge Expected in India: Up to ₹12,000 Increase
Computing
Google Faces €890 Million Penalty in Landmark EU Digital Markets Act Enforcement

European regulators have imposed a hefty fine of €890 million (approximately $1 billion) on Google, citing the company's...

CNBC | Jul 23, 2026, 10:25
Google Faces €890 Million Penalty in Landmark EU Digital Markets Act Enforcement
Startups
Unlock Exclusive Insights at TechCrunch Disrupt 2026 by Volunteering

Volunteering at TechCrunch Disrupt 2026 is more than just securing a complimentary three-day entry; it's an unparalleled...

TechCrunch | Jul 23, 2026, 14:30
Unlock Exclusive Insights at TechCrunch Disrupt 2026 by Volunteering
AI
Investors React as AI Investment Woes Weigh on Tesla and Alphabet Shares

Shares of both Alphabet and Tesla experienced significant declines in premarket trading on Thursday, driven by concerns ...

CNBC | Jul 23, 2026, 08:35
Investors React as AI Investment Woes Weigh on Tesla and Alphabet Shares
View All News