BotBeat
...
← Back

> ▌

MicrosoftMicrosoft
POLICY & REGULATIONMicrosoft2026-06-08

Major Security Breach: Malware-Laced Microsoft Repositories Target Claude Code and Gemini CLI Users

Key Takeaways

  • ▸Microsoft disabled 73 repositories across Azure, Durable Task, and AI sample organizations on June 5 after TeamPCP planted credential-harvesting malware
  • ▸The malware targeted users of AI coding tools including Claude Code, Gemini CLI, Cursor, and VS Code when they opened compromised repositories
  • ▸TeamPCP, a prolific supply chain attack group, had previously compromised Microsoft's durabletask package in May, indicating a sustained campaign against developer infrastructure
Source:
Hacker Newshttps://www.404media.co/microsoft-hacked-to-deliver-malware-to-claude-and-gemini-users/↗

Summary

Microsoft shut down more than 70 of its own GitHub repositories on June 5 after discovering malicious code planted within them by the threat actor group TeamPCP. Cybersecurity researchers from StepSecurity identified malware that would harvest users' credentials when they opened the compromised repositories in AI coding tools including Claude Code (Anthropic), Gemini CLI (Google), Cursor, and VS Code. The malicious repositories spanned four GitHub organizations, including Azure Functions, Durable Task, and AI sample applications, representing a widespread supply chain attack targeting the developer ecosystem.

The malware operated by planting configuration files that would activate when users opened repositories in their AI coding environments, creating a direct vector for credential theft among AI developers. TeamPCP had previously compromised Microsoft's durabletask package in May 2026, publishing three malicious versions before this escalated attack. GitHub disabled 73 repositories in a rapid 105-second action on June 5, with repositories now displaying GitHub staff notices indicating violations of terms of service.

The incident reveals a significant security failure in the supply chain for AI development tools. Any GitHub Actions workflows that relied on the disabled repositories will no longer function. The breach raises critical questions about how Microsoft failed to fully remediate its infrastructure after the initial durabletask compromise in May, and the broader implications for supply chain security in the AI developer ecosystem.

  • The breach broke GitHub Actions workflows dependent on these repositories and suggests incomplete remediation from the earlier May compromise
AI AgentsCybersecurityPrivacy & Data

More from Microsoft

MicrosoftMicrosoft
PRODUCT LAUNCH

Microsoft Launches MAI-Image-2.5-Pro and MAI-Voice-2-Flash in Public Preview

2026-07-23
MicrosoftMicrosoft
UPDATE

Microsoft Xbox Tests Ad-Supported Free Game Streaming for Insiders

2026-07-23
MicrosoftMicrosoft
UPDATE

Microsoft Retires Free Copilot Deep Research, Moves Feature Behind Microsoft 365 Paywall

2026-07-23

Comments

Suggested

SLAC National Accelerator LaboratorySLAC National Accelerator Laboratory
RESEARCH

SLAC Launches AI Multi-Agent Framework to Accelerate Critical Metal Recovery from Spent Batteries

2026-07-23
AnthropicAnthropic
PRODUCT LAUNCH

DingDuff: Claude-Powered Legal Research Tool Launches with Tip-Jar Model

2026-07-23
GitHubGitHub
UPDATE

GitHub Overhauls Bug Bounty Program with Two-Tier System to Combat AI Report Flood

2026-07-23
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us