{"id":526253,"date":"2026-06-09T13:38:28","date_gmt":"2026-06-09T13:38:28","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/526253\/"},"modified":"2026-06-09T13:38:28","modified_gmt":"2026-06-09T13:38:28","slug":"microsofts-open-source-tools-were-hacked-to-steal-passwords-of-ai-developers","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/526253\/","title":{"rendered":"Microsoft&#8217;s open source tools were hacked to steal passwords of AI developers"},"content":{"rendered":"<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Microsoft has cut off access to dozens of its open source projects hosted on GitHub as it investigates how hackers apparently breached the projects and injected password-stealing malware into the code.<\/p>\n<p class=\"wp-block-paragraph\">Many of the affected projects relate to Microsoft\u2019s cloud service Azure and other tools used by developers to code with AI development apps, such as Claude Code, Gemini\u2019s command line interface, and VS Code.<\/p>\n<p class=\"wp-block-paragraph\">According to <a href=\"https:\/\/cloudsmith.com\/blog\/miasma-worms-path-of-destruction\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">security firm Cloudsmith<\/a> and community-driven malware analysis site <a href=\"https:\/\/opensourcemalware.com\/blog\/miasma-reaches-azure\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">OpenSourceMalware<\/a>, which were some of the first to flag the hack, the malware allowed the hackers to steal the users\u2019 passwords and other sensitive credentials when they opened the compromised tools in their AI coding apps.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s not immediately known how many people have downloaded the affected tools.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft confirmed it pulled the repos, as first reported by <a href=\"https:\/\/www.404media.co\/microsoft-hacked-to-deliver-malware-to-claude-and-gemini-users\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">404 Media<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft spokesperson Ben Hope told TechCrunch that the company has \u201ctemporarily removed some repositories as we investigated potential malicious content.\u201d <\/p>\n<p class=\"wp-block-paragraph\">\u201cSome of these repos have been restored after review, while others may remain offline while work continues.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cAs part of our investigation, we notified a small number of customers who may have pulled down content from the affected repositories. We will continue to investigate, and if anything further is identified that requires customer action, we will reach out directly through our established support channels,\u201d added Hope.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft did not immediately provide the specific number of customers affected, when asked by TechCrunch.<\/p>\n<p class=\"wp-block-paragraph\">At least 70 projects belonging to Microsoft have been \u201cdisabled,\u201d per a message loading when trying to access the projects\u2019 pages on GitHub, a code-hosting site that Microsoft owns. \u201cAccess to this repository has been disabled by GitHub Staff due to a violation of GitHub\u2019s terms of service.\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1850\" height=\"876\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/06\/github-disabled.jpg\" alt=\"a screenshot showing a disabled github repo: reading \u2014 &quot;This repository has been disabled. Access to this repository has been disabled by GitHub Staff due to a violation of GitHub's terms of service. If you are the owner of the repository, you may reach out to GitHub Support for more information.&quot;\" class=\"wp-image-3130737\"  \/><strong>Image Credits:<\/strong>TechCrunch\/screenshot<\/p>\n<p class=\"wp-block-paragraph\">This is the latest example <a href=\"https:\/\/techcrunch.com\/2026\/05\/19\/hackers-have-compromised-dozens-of-popular-open-source-packages-in-an-ongoing-supply-chain-attack\/\" rel=\"nofollow noopener\" target=\"_blank\">in recent months<\/a> of hackers breaching widely popular open source projects with the aim of planting malware on a large number of users who have the code installed on their computers. These hacks are known as \u201csupply chain\u201d attacks as they target code that is often used in a large number of software products, or by a specific kind of user, which may be advantageous to hack as they sometimes have access to cloud systems and large amounts of customers\u2019 data.<\/p>\n<p class=\"wp-block-paragraph\">While it\u2019s not uncommon for sole developers of open source projects to be targeted by hackers \u2014 in some cases as part of <a href=\"https:\/\/techcrunch.com\/2026\/04\/06\/north-koreas-hijack-of-one-of-the-webs-most-used-open-source-projects-was-likely-weeks-in-the-making\/\" rel=\"nofollow noopener\" target=\"_blank\">long-running efforts to gain the trust of the developer<\/a> \u2014 it is rare for large tech giants like Microsoft, which have the resources to defend against these kinds of attacks, to get breached.<\/p>\n<p class=\"wp-block-paragraph\">This is Microsoft\u2019s second known breach over the past few weeks that has allowed hackers to compromise its open source projects, per <a href=\"https:\/\/arstechnica.com\/security\/2026\/06\/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Ars Technica<\/a>. In mid-May, security researchers said that Microsoft\u2019s open source project Durable Task, a tool that helps developers build apps, was hacked. OpenSourceMalware said that Microsoft\u2019s latest incident is a \u201cre-compromise\u201d of the Durable Task project, suggesting that Microsoft may not have eradicated the hackers on its first attempt or an entirely new, distinct breach.<\/p>\n<p class=\"wp-block-paragraph\">Updated with comment from Microsoft.<\/p>\n<p>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" rel=\"nofollow noopener\" target=\"_blank\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft has cut off access to dozens of its open source projects hosted on GitHub as it investigates&hellip;\n","protected":false},"author":2,"featured_media":526254,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[261],"tags":[291,289,290,5101,982,3600,18,13167,31845,19,17,305,929,82],"class_list":["post-526253","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-claude","tag-cybersecurity","tag-data-breach","tag-eire","tag-gemini","tag-github","tag-ie","tag-ireland","tag-microsoft","tag-open-source","tag-technology"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/116720429513421727","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/526253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=526253"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/526253\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/526254"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=526253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=526253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=526253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}