As cited
Copy frozen at (site build).
threat intel
For the 2nd time in weeks, Microsoft packages laced with credential stealer
Microsoft-owned open source packages were compromised with credential-stealing code that targeted developers using AI coding agents. GitHub disabled 73 malicious packages but initially did not clearly disclose the security threat, instead citing a terms of service violation. Microsoft acknowledged the potential malicious content only several days later in an email statement.
Why it matters: Developers who used AI agents to interact with these packages should assume their systems are compromised and audit for credential theft; organizations need to review their supply chain controls and AI agent usage policies for this attack vector.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
For the 2nd time in weeks, Microsoft packages laced with credential stealer
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
For the 2nd time in weeks, Microsoft packages laced with credential stealer
Microsoft's open source packages, numbering 73 across multiple repositories, were compromised to inject credential-stealing malware that activated when developers accessed them through artificial intelligence (AI) coding agents. GitHub initially disabled the packages for terms of service violations without disclosing the security incident, and Microsoft delayed public acknowledgment until the following Monday. Developers who used AI agents to interact with these packages should assume compromise of their systems.
Why it matters: Software developers relying on Microsoft open source packages and AI coding agents face credential theft and system compromise; immediate investigation and credential rotation are necessary for anyone who accessed these packages.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
For the 2nd time in weeks, Microsoft packages laced with credential stealer
Microsoft's open source packages, numbering 73 across multiple repositories, were compromised to inject credential-stealing malware that activated when developers accessed them through artificial intelligence (AI) coding agents. GitHub initially disabled the packages for terms of service violations without disclosing the security incident, and Microsoft delayed public acknowledgment until the following Monday. Developers who used AI agents to interact with these packages should assume compromise of their systems.
Why it matters: Software developers relying on Microsoft open source packages and AI coding agents face credential theft and system compromise; immediate investigation and credential rotation are necessary for anyone who accessed these packages.
- Source published
- First seen by Cybersecurity Tracker