Multiple Microsoft open-source tools have been implanted with data-stealing code.
TechCrunch
06-09 04:12
Ai Focus
Microsoft has taken dozens of GitHub open-source projects offline as part of an investigation into a suspected supply chain attack targeting AI developers.
Helpful
No.Help

Microsoft has suspended access to dozens of open-source projects on GitHub after these codebases were suspected of being hacked and infected with malware capable of stealing passwords and sensitive credentials. The affected projects are mostly related to Azure cloud services, and also include development tools that can be accessed in AI coding environments such as Claude Code, Gemini command-line tools, and VS Code.

At least 70 projects have been suspended.

TechCrunch, citing security firm Cloudsmith and malware analysis site OpenSourceMalware, reports that attackers have inserted data-stealing code into the relevant projects. Once users open these compromised tools in AI development applications, their passwords and other sensitive credentials could be stolen.

Microsoft has confirmed the removal of the relevant code repositories. According to information displayed on the GitHub page, at least 70 Microsoft projects have been disabled, with the page stating that these repositories were closed by GitHub staff for violating the GitHub Terms of Service.

It is unclear how many users have downloaded these affected tools, and Microsoft has not immediately explained the intrusion path or the scope of the impact.

The affected scope extends to the AI development chain.

Based on the disclosed information, this incident was not a single project failure, but rather affected multiple open-source tools for developers. Since these tools are likely integrated into daily development workflows, the attackers' target was clearly not just a single device, but rather an attempt to expand their reach through commonly used code components.

These types of attacks are often referred to as supply chain attacks. Attackers don't directly target end users; instead, they first compromise widely used code projects and then spread the attack to more users through development tools, dependencies, or software components. The harm from these attacks is often greater for developers who have access to cloud system privileges, keys, and customer data.

It may be related to the events of May.

The report noted that this is the second known security incident involving a Microsoft open-source project in recent weeks. In mid-May, security researchers stated that Microsoft's open-source project, Durable Task, had been compromised. This tool is primarily used to help developers build applications.

OpenSourceMalware believes this latest incident may be another breach of the Durable Task project. This implies two possibilities: either the attackers were not completely eliminated after the initial incident, or Microsoft has suffered another independent intrusion.

Large tech companies possess more comprehensive security resources, making such incidents less common. This concentrated decommissioning of Microsoft projects also demonstrates that open-source tools have become high-risk entry points for AI developers and cloud environment access.

Tip
$0
Like
0
Save
0
Views 888
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Speculation is escalating that Strategy is selling tokens again, but no large on-chain transfers have been observed yet.
After Strategy sold 32 bitcoins, the market speculated whether it would continue to reduce its holdings, but there are no signs of large-scale transfers to exchanges on the blockchain yet.
CoinPedia
·2026-06-08 13:01:22
211
AI tools are shifting to token-based billing, increasing cost pressures on businesses.
After GitHub Copilot switched to token-based billing, the issue of enterprise AI usage costs and budget control has come under scrutiny.
Wall Street CN
·2026-06-08 19:01:20
672
Foreign media: Multiple factors combined to suppress Bitcoin's price movement
NYDIG believes that the decline in Bitcoin is driven by multiple factors, with on-chain data nearing the bottom range, but the pullback is still milder than in historical bear markets.
CoinDesk
·2026-06-08 00:10:24
964
SEI pressured downwards, with open interest falling to low levels.
AMBCrypto reports that the SEI continued to weaken after falling below $0.049, with open interest in the derivatives market declining, long liquidations increasing, and trader sentiment becoming more cautious.
AMBCrypto
·2026-06-07 15:39:08
560
Pew survey: One in five American adults have used crypto assets
Pew Research states that approximately 19% of U.S. adults use crypto assets, with higher engagement among Republicans and younger men.
U.Today
·2026-06-09 05:11:47
587