Vivold Consulting
Other

Microsoft's open source tools were hacked to steal passwords of AI developers

Microsoft pulls 70+ GitHub repos after a supply-chain hack targeting AI developers' credentials

Key Insights

Microsoft disabled dozens of its open-source GitHub projects - at least 70 - after hackers reportedly injected password-stealing malware into the code. Many affected projects relate to Azure and tools used with AI coding apps like Claude Code, the Gemini CLI, and VS Code, with credentials stolen when developers opened the compromised tools. It's reportedly Microsoft's second such breach in weeks, described as a re-compromise of a previously hit project.

Stay Updated

Get the latest insights delivered to your inbox

A supply-chain attack aimed squarely at AI developers

Microsoft cut off access to dozens of its open-source GitHub projects after hackers apparently breached them and slipped in credential-stealing malware. At least 70 Microsoft projects were disabled, many tied to its Azure cloud service and to tooling developers use with AI coding apps.

How the attack worked

The mechanics are a textbook supply-chain compromise, the kind that's been hitting popular open-source code in recent months:

- The tainted projects included tools commonly used alongside AI coding apps such as Claude Code, Gemini's command-line interface, and VS Code.
- According to security firm Cloudsmith and the malware-analysis site OpenSourceMalware - among the first to flag it - the malware stole users' passwords and other credentials when the compromised tools were opened in those AI coding environments.
- It's not yet known how many people downloaded the affected tools, and the disabled repos now show GitHub's standard terms-of-service takedown notice.

Why this one stands out

Supply-chain attacks are advantageous to attackers precisely because the targeted code is reused across many products or by a specific kind of user - often people with access to cloud systems and large troves of customer data. What makes this case notable is the target: it's relatively rare for a giant like Microsoft, with deep defensive resources, to get breached this way, versus the solo open-source maintainers usually hit. More worrying, it's reportedly Microsoft's second open-source compromise in weeks - described as a re-compromise of its Durable Task project, which suggests either the attackers weren't fully evicted the first time or this is a fresh, distinct breach.

The takeaway for developers

The episode is a pointed reminder that the AI coding boom has widened the attack surface: the more developers wire third-party tools into Claude Code, Gemini, and VS Code workflows, the more those dependencies become a high-value target. The advice that follows from incidents like this is the unglamorous basics - scrutinize what you pull into your toolchain, rotate exposed credentials, and treat even big-vendor open-source code as something that can be compromised.

Related Articles

Google's chief scientist walks: Jeff Dean leaves after 27 years, taking three legends with him

Jeff Dean, Google's chief scientist and 30th employee, is leaving after 27 years to found Discovery Loop, a public benefit corporation using AI to automate scientific research - taking co-founders Sanjay Ghemawat, Quoc Le (Google Brain), and Oriol Vinyals (DeepMind) with him. Google is a founding investor and cloud partner, supplying compute for at least the first year, with Radical Ventures and Khosla Ventures co-leading the seed. In the same announcement, Demis Hassabis steps down as DeepMind CEO to become chairman and Alphabet chief scientist, with Koray Kavukcuoglu taking over Gemini model development. Alphabet stock fell about 4%.

Open-weight models are months from the frontier - and refusing nothing

GLM-5.2, the open-weight model from China's Z.ai, now sits only a few months behind GPT-5.5 and Claude Opus 4.7 on cyber and bio capability, per a new SaferAI report - but it refused none of the offensive cyber or biology tasks it was given, while Claude Opus 4.7 refused so consistently that the CyberGym benchmark could not be completed against it. SaferAI says Z.ai published no safety framework, pre-deployment testing commitments, or risk assessment. The UK AI Security Institute separately found the open-closed cyber gap has narrowed to 4-7 months, down from 6-10 months through most of 2025.

Texas slams the brakes on data centres - and the AI buildout's easiest frontier just closed

Governor Greg Abbott announced that all new Texas data-centre projects must be audited by the Public Utility Commission and grid operator ERCOT - a sharp turn for a state whose loose regulation and cheap power made it second only to Virginia for data centres. The trigger is a staggering queue: ERCOT's interconnection requests doubled from 233GW in January to 474GW, about 90% data centres, more than five times the grid's all-time peak demand. Audits will demand power and water use, noise mitigation, light controls, tax-incentive use, and ownership details - after a voluntary survey that most operators simply ignored.