
Microsoft has temporarily suspended access to numerous open-source projects on GitHub as it looks into a security breach that led to the injection of password-stealing malware into its code. Many of the compromised projects are associated with Microsoft's Azure cloud services and tools utilized by developers in AI programming applications, including Claude Code, Gemini's command line interface, and Visual Studio Code. According to cybersecurity experts from Cloudsmith and the community-driven site OpenSourceMalware, the malware enabled hackers to capture users' passwords and other sensitive information when developers interacted with the compromised tools. The exact number of users who have downloaded the affected software remains unclear. Microsoft has confirmed the removal of these repositories, as initially reported by 404 Media. A spokesperson acknowledged receiving inquiries but did not provide further comments at the moment. Currently, at least 70 of Microsoft's projects have been marked as “disabled” on GitHub, displaying a message indicating a violation of GitHub's terms of service. This incident is part of a troubling trend where hackers exploit popular open-source projects to deploy malware, targeting a wide range of users who might have the code installed on their systems. Such attacks are referred to as “supply chain” attacks, focusing on software that is commonly used in various products or by specific user groups, which can often include access to sensitive cloud systems and customer data. While smaller open-source projects frequently fall victim to such attacks, it is less common for large corporations like Microsoft, which usually possess the resources to safeguard against these threats, to experience such breaches. This marks Microsoft's second known incident in recent weeks involving the compromise of its open-source projects. Earlier in May, security researchers reported a hack of Microsoft's Durable Task project, which aids developers in app creation. OpenSourceMalware has indicated that the recent breach may be a “re-compromise” of the Durable Task project, raising concerns that previous security measures may not have fully eliminated the threat or that a new breach has occurred entirely.
Apple has unveiled a suite of developer tools designed to allow car manufacturers to integrate Apple Maps directly into ...
TechCrunch | Jul 23, 2026, 14:05
Apple is reportedly planning to raise prices for the iPhone 17 series in India, mirroring recent price hikes in Japan. S...
Business Today | Jul 23, 2026, 10:10
European regulators have imposed a hefty fine of €890 million (approximately $1 billion) on Google, citing the company's...
CNBC | Jul 23, 2026, 10:25
Volunteering at TechCrunch Disrupt 2026 is more than just securing a complimentary three-day entry; it's an unparalleled...
TechCrunch | Jul 23, 2026, 14:30
Shares of both Alphabet and Tesla experienced significant declines in premarket trading on Thursday, driven by concerns ...
CNBC | Jul 23, 2026, 08:35