AI Briefing
KO

Microsoft's Open Source Tools Hacked to Steal AI Developers' Passwords

·2026.06.09 16:33

Key point

Microsoft's open source projects were hacked to distribute malware that steals credentials from AI development tool users.

Details

Microsoft has blocked access to dozens of its open source projects hosted on GitHub while it investigates malicious code injected into the repositories.

This attack is part of a Supply Chain Attack, in which hackers inserted password-stealing malware into the code to steal users' sensitive credentials. The affected projects include the following AI development-related tools:

  • Claude Code related tools
  • Gemini command-line interface (CLI)
  • VS Code related tools
  • Other projects related to Azure cloud services

Currently, about more than 70 projects have been disabled due to violations of GitHub's terms of service. Microsoft stated that it has restored some repositories after review, and is directly notifying a small number of customers believed to have been affected.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.