BotBeat
...
← Back

> ▌

MicrosoftMicrosoft
UPDATEMicrosoft2026-06-09

Microsoft's Open Source Projects Compromised in Password-Stealing Malware Attack

Key Takeaways

  • ▸At least 70 Microsoft open source projects were compromised with password-stealing malware affecting Azure and AI development tools
  • ▸Malware was designed to steal developer passwords and credentials when tools were used in AI coding applications
  • ▸This is Microsoft's second major breach of open source projects in recent weeks, suggesting possible persistent access or recurring vulnerabilities
Source:
Hacker Newshttps://techcrunch.com/2026/06/08/microsofts-open-source-tools-were-hacked-to-steal-passwords-of-ai-developers/↗

Summary

Microsoft has temporarily disabled access to at least 70 of its open source projects hosted on GitHub after discovering they were breached and injected with password-stealing malware. The compromised projects include tools related to Microsoft's Azure cloud service and widely-used AI development applications such as Claude Code, Gemini's CLI, and VS Code. According to security firms Cloudsmith and OpenSourceMalware, the malware was designed to steal users' passwords and other sensitive credentials when the tools were opened within AI coding environments.

The exact scale of the breach remains unclear, with Microsoft confirming it has "temporarily removed some repositories" for investigation and notifying a limited number of potentially affected customers. Some repositories have been restored after review, while others remain offline pending further investigation. This marks the second known breach of Microsoft's open source projects in recent weeks—following the May compromise of the Durable Task project—raising concerns about whether Microsoft adequately eradicated the initial breach or if this represents an entirely separate incident.

The incident exemplifies the growing threat of supply chain attacks targeting open source projects, where attackers compromise widely-used code to gain access to downstream users who often have elevated permissions to cloud systems and customer data. While such attacks typically target individual open source developers, it is relatively rare for major technology companies with substantial security resources like Microsoft to suffer such breaches.

  • The incident exemplifies supply chain attacks—a growing threat targeting widely-used code to compromise downstream users with system and cloud access
CybersecurityPrivacy & DataOpen Source

More from Microsoft

MicrosoftMicrosoft
PRODUCT LAUNCH

Microsoft Launches MAI-Image-2.5-Pro and MAI-Voice-2-Flash in Public Preview

2026-07-23
MicrosoftMicrosoft
UPDATE

Microsoft Xbox Tests Ad-Supported Free Game Streaming for Insiders

2026-07-23
MicrosoftMicrosoft
UPDATE

Microsoft Retires Free Copilot Deep Research, Moves Feature Behind Microsoft 365 Paywall

2026-07-23

Comments

Suggested

Google / AlphabetGoogle / Alphabet
RESEARCH

Researchers Demonstrate Timing-Based Attacks That Steal LLM Architecture Secrets

2026-07-24
Bad Theory LabsBad Theory Labs
OPEN SOURCE

Bad Theory Labs Open-Sources BTL-3, a 27B Agent Model for Agentic Coding

2026-07-24
AnthropicAnthropic
POLICY & REGULATION

Anthropic's Claude Cowork Sandbox Escape Disclosed: Researchers Demonstrate Path to Host Filesystem Access

2026-07-24
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us