Developer Tools

Microsoft GitHub repos hacked, malware steals AI developers' credentials

70+ projects compromised; hackers injected password-stealing code into Azure and AI tools.

Deep Dive

Microsoft has temporarily removed access to dozens of its open-source GitHub repositories after security researchers discovered hackers had injected password-stealing malware into the code. The affected projects include tools related to Microsoft’s Azure cloud service and popular AI development environments such as Claude Code, Google Gemini’s command-line interface, and VS Code. According to security firm Cloudsmith and the OpenSourceMalware community, the injected malware is designed to steal users' passwords and other sensitive credentials when they open the compromised tools in their AI coding applications. At least 70 repositories have been disabled, displaying a message about violating GitHub's terms of service.

This incident marks the second time in recent weeks that Microsoft's open-source projects have been compromised. In mid-May, the company's Durable Task project — a library for building durable applications — was similarly breached. Researchers at OpenSourceMalware describe the latest attack as a “re-compromise” of that same project, suggesting hackers may have re-entered after the initial cleanup. While supply-chain attacks on smaller open-source projects are common, it is unusual for a tech giant like Microsoft to be hit repeatedly. Microsoft confirmed it is investigating and has notified a small number of customers who may have downloaded the malicious code. The company did not disclose the exact number of affected users.

Key Points
  • At least 70 Microsoft GitHub repos were disabled after hackers injected password-stealing malware into AI developer tools like Claude Code and Gemini CLI.
  • The malware triggers when developers open compromised code in VS Code or other IDEs, stealing credentials and cloud access tokens.
  • This is Microsoft's second open-source breach in weeks, following the Durable Task incident; researchers call it a 're-compromise' of the same project.

Why It Matters

Supply-chain attack on Microsoft's repos puts countless AI developers' credentials and cloud access at risk.

📬 Get the top 10 AI stories daily