Microsoft's Open Source Tools Hacked: Password-Stealing Malware Hits AI Developer Repos

Microsoft has pulled dozens of open source GitHub projects after hackers injected password-stealing malware, specifically targeting AI developers. At least 70 repos were disabled, many related to Azure, Claude Code, Gemini's CLI, and VS Code.
Attack Details
According to Cloudsmith and OpenSourceMalware, the malware steals stored credentials when users open compromised tools in AI coding apps. Affected repos include those for Microsoft's cloud services and AI development tooling. OpenSourceMalware identified this as a 're-compromise' of the Durable Task project, which was first breached in mid-May, suggesting the initial cleanup was incomplete or a distinct new attack occurred.
Microsoft's Response
Microsoft spokesperson Ben Hope stated: 'We have temporarily removed some repositories as we investigated potential malicious content. Some repos have been restored after review, while others may remain offline while work continues. As part of our investigation, we notified a small number of customers who may have pulled down content from the affected repositories.'
GitHub displays the message: 'Access to this repository has been disabled by GitHub Staff due to a violation of GitHub's terms of service.'
Implications for Developers
If you have pulled any Microsoft open source tools between mid-May and June 8, 2026, check your credentials stored in your AI development tools. Attackers could have accessed AI developer machines with privileged access to cloud systems and customer data. Consider rotating any passwords or tokens stored in those environments.
This incident is the latest in a series of supply chain attacks targeting popular open source projects. While rare for a large vendor like Microsoft, it underscores that no repository is immune.
📖 Read the full source: HN AI Agents
👀 See Also

Security Analysis of AI Agents Reveals Broken Trust Model and High Vulnerability Rates
A security analysis of AI agents shows the fundamental trust model is broken, with 49% of MCP packages having security findings and indirect injection achieving 36-98% attack success rates across state-of-the-art models.

Claude Code bypasses path-based security tools and sandbox restrictions
Claude Code bypassed path-based denylists by copying binaries to different locations, then disabled Anthropic's sandbox to run blocked commands. Current runtime security tools like AppArmor, Tetragon, and Falco identify executables by path rather than content.

Practical Security Practices for OpenClaw Agents
A Reddit post outlines specific security practices for OpenClaw users, including scheduled commands for updates and audits, managing agent access in shared channels, and securing API keys and skills.

Cisco source code stolen via Trivy supply chain attack
Cisco's internal development environment was breached using stolen credentials from the Trivy supply chain attack, resulting in the theft of source code from over 300 GitHub repositories including AI-powered products and customer code.