Skip to content

ABC Tool

  • Home
  • About / Contect
    • PRIVACY POLICY
Microsoft’s open source tools were hacked to steal passwords of AI developers

Microsoft’s open source tools were hacked to steal passwords of AI developers

Posted on June 9, 2026 By safdargal12 No Comments on Microsoft’s open source tools were hacked to steal passwords of AI developers
Blog


Microsoft has cut off access to dozens of its open source projects hosted on GitHub as it investigates how hackers apparently breached the projects and injected password-stealing malware into the code.

Many of the affected projects relate to Microsoft’s cloud service Azure and other tools used by developers to code with AI development apps, such as Claude Code, Gemini’s command line interface, and VS Code.

According to security firm Cloudsmith and community-driven malware analysis site OpenSourceMalware, which were some of the first to flag the hack, the malware allowed the hackers to steal the users’ passwords and other sensitive credentials when they opened the compromised tools in their AI coding apps.

It’s not immediately known how many people have downloaded the affected tools.

Microsoft confirmed it pulled the repos, as first reported by 404 Media.

Microsoft spokesperson Ben Hope told TechCrunch that the company has “temporarily removed some repositories as we investigated potential malicious content.”

“Some of these repos have been restored after review, while others may remain offline while work continues.”

“As part of our investigation, we notified a small number of customers who may have pulled down content from the affected repositories. We will continue to investigate, and if anything further is identified that requires customer action, we will reach out directly through our established support channels,” added Hope.

Microsoft did not immediately provide the specific number of customers affected, when asked by TechCrunch.

At least 70 projects belonging to Microsoft have been “disabled,” per a message loading when trying to access the projects’ pages on GitHub, a code-hosting site that Microsoft owns. “Access to this repository has been disabled by GitHub Staff due to a violation of GitHub’s terms of service.”

Image Credits:TechCrunch/screenshot

This is the latest example in recent months of hackers breaching widely popular open source projects with the aim of planting malware on a large number of users who have the code installed on their computers. These hacks are known as “supply chain” attacks as they target code that is often used in a large number of software products, or by a specific kind of user, which may be advantageous to hack as they sometimes have access to cloud systems and large amounts of customers’ data.

While it’s not uncommon for sole developers of open source projects to be targeted by hackers — in some cases as part of long-running efforts to gain the trust of the developer — it is rare for large tech giants like Microsoft, which have the resources to defend against these kinds of attacks, to get breached.

This is Microsoft’s second known breach over the past few weeks that has allowed hackers to compromise its open source projects, per Ars Technica. In mid-May, security researchers said that Microsoft’s open source project Durable Task, a tool that helps developers build apps, was hacked. OpenSourceMalware said that Microsoft’s latest incident is a “re-compromise” of the Durable Task project, suggesting that Microsoft may not have eradicated the hackers on its first attempt or an entirely new, distinct breach.

Updated with comment from Microsoft.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



Source link

Post Views: 3

Post navigation

❮ Previous Post: Apple may have pulled a Samsung by leaking iPhone Ultra details
Next Post: Everything Announced at WWDC26 – CNET ❯

You may also like

Making sense of the debate over AI psychosis
Blog
Making sense of the debate over AI psychosis
June 1, 2026
Lovable signs multiyear deal with Google Cloud to up usage 5x, source says
Blog
Lovable signs multiyear deal with Google Cloud to up usage 5x, source says
June 4, 2026
Make Linux servers fun again!
Blog
Make Linux servers fun again!
April 24, 2026
There’s only one I’d choose
Blog
There’s only one I’d choose
June 6, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Evotrex raises $30M to build the RV that doesn’t need a charging station
  • Xiaomi 17T series lands in China, 17T gets battery boost
  • 5 biggest upgrades vs. Opus 4.7
  • Apple’s Upgraded Siri AI Promises to Do More. I’m Not Sure I Want That
  • The fastest way to hit Google AI Pro limits (and how to avoid it)

Recent Comments

  1. Last Chance for Big Savings on TechCrunch Disrupt 2026 Tickets – Artiverse on 5 days left: Save up to $410 on Disrupt 2026 passes

Archives

  • June 2026
  • May 2026
  • April 2026

Categories

  • Blog

Copyright © 2026 ABC Tool.

Theme: Oceanly News by ScriptsTown