AI Briefing
KO

Microsoft's open-source tools hacked to steal passwords from AI developers

·2026.06.10 09:42

Key point

GitHub-hosted, Microsoft-owned open-source projects were hacked in a supply chain attack that steals credentials from users of AI development tools.

Details

Dozens of open-source projects hosted on GitHub were compromised by hackers, who injected password-stealing malware into the code. Microsoft has blocked access to the affected projects and is investigating.

The affected projects are closely tied to tools used with Azure cloud services and AI coding apps such as Claude Code, Gemini CLI, and VS Code. When users run the infected tools, passwords and sensitive credentials are stolen.

This incident is part of a series of supply chain attacks that have occurred over recent months, marking the second time in recent weeks that one of Microsoft's open-source projects has been compromised. Hackers are targeting highly trusted open-source projects to gain access to cloud CLIs and sensitive information stored on developers' machines.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.