Microsoft’s GitHub Repos Poisoned in Supply Chain Attack Targeting AI Developers
Microsoft has yanked dozens of its open-source projects from GitHub after hackers injected password-stealing malware into the code. The compromised repositories include tools tied to Azure and popular AI development environments like Claude Code, Gemini’s CLI, and VS Code.
Security researchers at Cloudsmith and OpenSourceMalware were among the first to spot the breach. The malware activated when developers opened the infected tools in their AI coding apps, capturing login credentials and other sensitive data. Microsoft has not disclosed how many users downloaded the compromised code.
A Microsoft spokesperson confirmed the company “temporarily removed some repositories as we investigated potential malicious content.” Some repos have been restored; others remain offline. Microsoft also notified a small number of customers who may have pulled the affected files.
At least 70 Microsoft projects are currently disabled on GitHub, displaying a message that access was revoked for violating GitHub’s terms of service.
This is the second time in recent weeks that Microsoft’s open-source code has been breached. In mid-May, the Durable Task project—a tool for building applications—was compromised. OpenSourceMalware described this latest incident as a “re-compromise” of that same project, suggesting the initial cleanup may have failed or that a separate attack occurred.
Supply chain attacks like this target widely used code to infect many users at once. While smaller developers are frequent victims, it’s uncommon for a resource-rich company like Microsoft to suffer such breaches.
Source: TechCrunch
dArt Studio installs AI for local businesses in Broward & Palm Beach County, FL. We reply within 1 business hour.