Multiple Microsoft open-source tools have been implanted with data-stealing code.
TechCrunch
2h ago
Ai Focus
Microsoft has taken dozens of GitHub open-source projects offline as part of an investigation into a suspected supply chain attack targeting AI developers.
Helpful
No.Help

Microsoft has suspended access to dozens of open-source projects on GitHub after these codebases were suspected of being hacked and infected with malware capable of stealing passwords and sensitive credentials. The affected projects are mostly related to Azure cloud services, and also include development tools that can be accessed in AI coding environments such as Claude Code, Gemini command-line tools, and VS Code.

At least 70 projects have been suspended.

TechCrunch, citing security firm Cloudsmith and malware analysis site OpenSourceMalware, reports that attackers have inserted data-stealing code into the relevant projects. Once users open these compromised tools in AI development applications, their passwords and other sensitive credentials could be stolen.

Microsoft has confirmed the removal of the relevant code repositories. According to information displayed on the GitHub page, at least 70 Microsoft projects have been disabled, with the page stating that these repositories were closed by GitHub staff for violating the GitHub Terms of Service.

It is unclear how many users have downloaded these affected tools, and Microsoft has not immediately explained the intrusion path or the scope of the impact.

The affected scope extends to the AI development chain.

Based on the disclosed information, this incident was not a single project failure, but rather affected multiple open-source tools for developers. Since these tools are likely integrated into daily development workflows, the attackers' target was clearly not just a single device, but rather an attempt to expand their reach through commonly used code components.

These types of attacks are often referred to as supply chain attacks. Attackers don't directly target end users; instead, they first compromise widely used code projects and then spread the attack to more users through development tools, dependencies, or software components. The harm from these attacks is often greater for developers who have access to cloud system privileges, keys, and customer data.

It may be related to the events of May.

The report noted that this is the second known security incident involving a Microsoft open-source project in recent weeks. In mid-May, security researchers stated that Microsoft's open-source project, Durable Task, had been compromised. This tool is primarily used to help developers build applications.

OpenSourceMalware believes this latest incident may be another breach of the Durable Task project. This implies two possibilities: either the attackers were not completely eliminated after the initial incident, or Microsoft has suffered another independent intrusion.

Large tech companies possess more comprehensive security resources, making such incidents less common. This concentrated decommissioning of Microsoft projects also demonstrates that open-source tools have become high-risk entry points for AI developers and cloud environment access.

Tip
$0
Like
0
Save
0
Views 875
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Anthropic stated that Claude has generated the majority of production code.
Anthropic stated that Claude currently generates over 80% of the company's production code and can continuously execute software engineering tasks for up to 12 hours.
CoinPedia
·2026-06-05 10:58:11
839
Microsoft discloses Claude Code vulnerability that could steal GitHub credentials
Microsoft stated that Claude Code's GitHub Actions previously contained a hint injection vulnerability, which allowed attackers to use GitHub content to trick an AI agent into reading and distributing sensitive credentials. Anthropic has since fixed this vulnerability.
Coinpaper
·2026-06-07 04:59:48
983
Most of the funds stolen from Kelp DAO have been transferred.
Most of the stolen funds from Kelp DAO have been transferred, leaving only about $1.7 million in the original wallet, making recovery more difficult.
CoinPedia
·2026-06-02 14:15:06
390
Cardano's data platform TapTools has been shut down.
TapTools announced the initiation of the shutdown process, stating that the loss of senior executives, a shortage of technical teams, and high costs made it difficult for the platform to continue operating.
Coinpaper
·2026-06-03 16:35:35
648
Twelve Fortune 500 companies in the United States have been in existence for over 200 years.
Fortune magazine listed 12 of the US 500 companies that have been around for over 200 years. Banks and insurance companies accounted for a high proportion of these companies, and long-term strategy and risk management were considered common features.
Fortune
·2026-06-06 21:30:29
819