BotBeat
...
← Back

> ▌

MicrosoftMicrosoft
UPDATEMicrosoft2026-06-09

Microsoft's Open Source Projects Compromised in Password-Stealing Malware Attack

Key Takeaways

  • ▸At least 70 Microsoft open source projects were compromised with password-stealing malware affecting Azure and AI development tools
  • ▸Malware was designed to steal developer passwords and credentials when tools were used in AI coding applications
  • ▸This is Microsoft's second major breach of open source projects in recent weeks, suggesting possible persistent access or recurring vulnerabilities
Source:
Hacker Newshttps://techcrunch.com/2026/06/08/microsofts-open-source-tools-were-hacked-to-steal-passwords-of-ai-developers/↗

Summary

Microsoft has temporarily disabled access to at least 70 of its open source projects hosted on GitHub after discovering they were breached and injected with password-stealing malware. The compromised projects include tools related to Microsoft's Azure cloud service and widely-used AI development applications such as Claude Code, Gemini's CLI, and VS Code. According to security firms Cloudsmith and OpenSourceMalware, the malware was designed to steal users' passwords and other sensitive credentials when the tools were opened within AI coding environments.

The exact scale of the breach remains unclear, with Microsoft confirming it has "temporarily removed some repositories" for investigation and notifying a limited number of potentially affected customers. Some repositories have been restored after review, while others remain offline pending further investigation. This marks the second known breach of Microsoft's open source projects in recent weeks—following the May compromise of the Durable Task project—raising concerns about whether Microsoft adequately eradicated the initial breach or if this represents an entirely separate incident.

The incident exemplifies the growing threat of supply chain attacks targeting open source projects, where attackers compromise widely-used code to gain access to downstream users who often have elevated permissions to cloud systems and customer data. While such attacks typically target individual open source developers, it is relatively rare for major technology companies with substantial security resources like Microsoft to suffer such breaches.

  • The incident exemplifies supply chain attacks—a growing threat targeting widely-used code to compromise downstream users with system and cloud access
CybersecurityPrivacy & DataOpen Source

More from Microsoft

MicrosoftMicrosoft
PARTNERSHIP

NHS England to Deploy Copilot to 505,000 Staff, Citing 43-Minute Daily Productivity Gains

2026-06-08
MicrosoftMicrosoft
RESEARCH

Miasma Worm Supply Chain Attack Escalates: Malicious Commits Hit Microsoft Azure Repositories, Target AI Coding Agents

2026-06-08
MicrosoftMicrosoft
POLICY & REGULATION

Major Security Breach: Malware-Laced Microsoft Repositories Target Claude Code and Gemini CLI Users

2026-06-08

Comments

Suggested

Hugging FaceHugging Face
OPEN SOURCE

OpenEnv Goes Community-First: Major AI Organizations Back Open Source Agent Training Framework

2026-06-09
KnosticKnostic
PARTNERSHIP

VirusTotal Partners with Knostic to Add AI-Powered Security Analysis for VS Code Extensions

2026-06-09
AnthropicAnthropic
RESEARCH

Research Study Reveals How Developers Configure Agentic AI Coding Tools

2026-06-09
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us