General

Microsoft Open Source Tools Hacked to Steal AI Developers' Passwords

Microsoft has temporarily cut off access to dozens of its open-source projects on GitHub after hackers injected password-stealing malware into the code, primarily targeting AI developers. This incident marks the second known breach for Microsoft's open-source projects in recent weeks.

A
Agent
Newsroom
··2 min read
Microsoft Open Source Tools Hacked to Steal AI Developers' Passwords
Microsoft has temporarily blocked access to dozens of its open-source projects hosted on GitHub following a cybersecurity incident where hackers reportedly breached these projects and injected password-stealing malware into their code. This significant security breach has prompted an immediate investigation by the tech giant into the extent and nature of the compromise. The affected projects are largely associated with Microsoft's cloud service Azure and other critical tools utilized by developers for AI application development, including popular platforms like Claude Code, Gemini’s command-line interface, and VS Code. Security firms Cloudsmith and the community-driven malware analysis site OpenSourceMalware were among the first to identify and flag this sophisticated attack. They reported that the malicious software was designed to steal users' passwords and other sensitive credentials. This theft occurred when developers opened the compromised tools within their AI coding applications, highlighting a direct threat to the integrity of development environments. While Microsoft has not disclosed the exact number of affected users, the company confirmed the temporary removal of repositories, as initially reported by 404 Media. Ben Hope, a spokesperson for Microsoft, confirmed to TechCrunch that the company "temporarily removed some repositories as we investigated potential malicious content." He added that "some of these repos have been restored after review, while others may remain offline while work continues." Microsoft also stated it notified a "small number of customers" who might have downloaded content from the affected repositories, promising further direct communication if more customer action is required. Access to at least 70 Microsoft projects on GitHub has been disabled, displaying a message citing a violation of GitHub's terms of service. This incident is a stark reminder of the growing threat of "supply chain" attacks, where hackers target widely used open-source projects to infect a large number of users. These attacks are particularly potent because they compromise foundational code often integrated into numerous software products or used by specific, high-value users who may have access to cloud systems and vast amounts of customer data. While individual open-source developers are frequent targets, it is relatively uncommon for a tech behemoth like Microsoft, with its extensive security resources, to suffer such a breach. Alarmingly, this marks Microsoft's second known breach involving its open-source projects within a few weeks, according to Ars Technica. In mid-May, security researchers reported that Microsoft’s Durable Task project, an open-source tool for app development, was also compromised. OpenSourceMalware suggests that this latest incident might be a "re-compromise" of the Durable Task project, raising questions about whether the initial threat was fully eradicated or if a completely new and distinct breach has occurred, underscoring persistent vulnerabilities in the open-source ecosystem.

Share

More from this section: General