Microsoft Hacked: Malware Planted in GitHub Repos Targets Claude and Gemini Users

✍️ OpenClawRadar📅 Published: June 9, 2026🔗 Source
Microsoft Hacked: Malware Planted in GitHub Repos Targets Claude and Gemini Users
Ad

Microsoft has shut down over 70 of its own GitHub repositories, including those related to Azure and AI coding agents, after a breach where hackers planted malware that harvests credentials from AI coding tool users, according to 404 Media and security researchers.

Attack Vector: Malware in Microsoft's Own Repos

Hackers compromised Microsoft's repositories and planted malicious code. The malware is designed to steal credentials when opened in AI coding tools like Claude Code or Gemini CLI. One researcher identified a specific compromised package but details are limited as Microsoft investigates.

Scope and Response

Microsoft took the unusual step of disabling more than 70 of its own repositories across GitHub. The repositories included code for Azure and AI coding agent integrations, making the breach particularly dangerous for developers using these tools.

Ad

Impact on AI Coding Agents

AI coding agents like Claude Code and Gemini CLI often execute code from repositories to perform tasks. If a developer clones a compromised repo and opens it in one of these tools, the malware can silently exfiltrate API keys, tokens, or other credentials. The attack specifically targets users of these popular AI CLI tools.

What Developers Should Do

If you have recently cloned any Microsoft GitHub repositories — especially those related to Azure or AI coding — check for suspicious files or dependencies. Avoid running untrusted code in Claude Code or Gemini CLI. Rotate any credentials that may have been exposed. Monitor GitHub for official updates from Microsoft on which repositories were affected.

📖 Read the full source: HN AI Agents

Ad

👀 See Also

Introducing SkillFence: The New Runtime Monitor That Watches What Skills Actually Do
Security

Introducing SkillFence: The New Runtime Monitor That Watches What Skills Actually Do

SkillFence offers a breakthrough in monitoring AI agent actions, addressing the need for transparency and security in AI-driven environments. Discover how this innovative tool can enhance control over autonomous processes.

OpenClawRadar
OpenClaw Security Gap Addressed by Agentic Power of Attorney (APOA) Spec
Security

OpenClaw Security Gap Addressed by Agentic Power of Attorney (APOA) Spec

A developer has published an open specification called Agentic Power of Attorney (APOA) to address security concerns in OpenClaw, where agents currently access services like email and calendar with only natural language instructions as guardrails. The spec proposes per-service permissions, time-bounded access, audit trails, revocation, and credential isolation.

OpenClawRadar
AI-Built Apps Are Fragile: Why Small Changes Break Data Isolation and Permissions
Security

AI-Built Apps Are Fragile: Why Small Changes Break Data Isolation and Permissions

Developers report that AI-generated apps (via Claude Code, Cursor) silently break login, permissions, and data isolation when small changes are made, because AI models lack understanding of original system intent like ownership rules.

OpenClawRadar
Hackerbot-Claw: AI Bot Exploiting GitHub Actions Workflows
Security

Hackerbot-Claw: AI Bot Exploiting GitHub Actions Workflows

An AI-powered bot called hackerbot-claw executed a week-long automated attack campaign against CI/CD pipelines, achieving remote code execution in at least 4 out of 6 targets including Microsoft, DataDog, and CNCF projects. The bot used 5 different exploitation techniques and exfiltrated a GitHub token with write permissions.

OpenClawRadar