Skip to main content
See every side of every news story
Published loading...Updated

For the 2nd time in weeks, Microsoft packages laced with credential stealer

At least 70 projects were disabled after a worm injected code that stole passwords and cloud secrets from developers using AI coding tools.

  • On Friday, Microsoft disabled 73 GitHub repositories after automated systems detected the Miasma worm injecting password-stealing malware into cryptographically verified open-source packages used by developers globally.
  • Compromised contributor accounts allowed the Miasma worm to inject malicious code, specifically targeting cloud credentials, Kubernetes configurations, and over 90 developer tool settings when developers opened the affected code in AI agents.
  • The incident represents a re-compromise of Durable Task, with security researchers linking the attack to cybercrime group TeamPCP, responsible for a similar breach last month affecting Red Hat packages.
  • Rather than warning developers, GitHub disabled the repositories citing "a violation of GitHub's terms of service," leaving users to discover the security breach independently on their own.
  • Microsoft continues promoting Enterprise Live Migrations to move customers onto GitHub, betting that its AI-native development tools outweigh the ongoing supply-chain risks despite these security challenges.
Insights by Ground AI
Podcasts & Opinions

28 Articles

Lean Right

In a move aimed at bolstering security, Microsoft confirmed it temporarily removed some GitHub repositories after they were compromised. Microsoft restores some GitHub repositories and keeps others offline while the Miasma investigation continues. Microsoft confirmed on Monday that it temporarily removed some GitHub repositories in response to a recent security incident that compromised 73 of its open-source projects to inject code-stealing malw…

Lean Left

The incident marked the second successful attack on Microsoft's open-source tools in recent weeks. Microsoft temporarily blocked access to over 70 of its own open-source projects on the GitHub platform due to a supply chain hack. Attackers infected the codebase of Azure cloud tools and popular AI developer assistants with malware designed to steal passwords and confidential data, according to RBC-Ukraine, citing 404 Media. Hack mechanics The at…

Read Full Article
TechCrunchTechCrunch
Reposted by
New Movies & TV Shows, Trailers & ReviewsNew Movies & TV Shows, Trailers & Reviews
Center

Microsoft's open source tools were hacked to steal passwords of AI developers

Microsoft shut down dozens of GitHub code repositories for Azure and AI coding tools after a reported hack.

·United States
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 67% of the sources are Center
67% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Register broke the news on Monday, June 8, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal