Home
Microsoft open source project hacked, AI development tools infected with password-stealing malware
Microsoft recently removed dozens of open-source repositories from GitHub after hackers infiltrated them and injected malicious code designed to steal user passwords. The move prompted strong reactions across the developer community.

Precision Targeting of AI Developers
Security firm Cloudsmith and malware analysis platform OpenSourceMalware were the first to detect the anomaly. Reports indicate that the affected projects were primarily tied to Microsoft Azure cloud services and several popular AI development tools, including components associated with AI coding applications like Claude Code, the Gemini CLI, and VS Code.
The attackers executed targeted software supply chain attacks by embedding malicious code into these tools. When developers opened the compromised tools locally through AI coding applications, the malware ran silently, attempting to steal local passwords and other sensitive credentials.
Emergency Removal for Risk Investigation
Microsoft later confirmed that, as a security measure, it had temporarily taken down at least 70 related code repositories while investigating potential malicious content. Some have since been restored after security reviews, while others remain disabled due to ongoing risks.
During the internal investigation, Microsoft sent security notifications to a small number of customers who may have downloaded affected content. Despite Microsoft’s strong security resources and protections, this marks the second time in recent weeks that its open-source projects have been compromised—highlighting the serious security challenges facing the current AI development ecosystem.
Related article
DeepMind CEO Hassabis: I sleep six hours a day, usually feel energetic around 1 a.m.
Fortune recently featured an interview with Demis Hassabis, CEO of Google DeepMind, revealing his unconventional approach to rest and productivity. Hassabis disclosed that he sleeps very little, structuring his waking hours into two distinct work blo
OpenAI, Anthropic Vie for Market Share Despite Revenue Shortfalls
Despite recent reports suggesting OpenAI missed revenue targets, creating pressure on tech stocks this Tuesday, private AI lab investors remain resilient. Seasoned backers have confirmed they will not reduce investment despite negative media coverage
California AV Compliance: A New Era of Tickets, Geofences, and 1M Miles
Guident operates an AuveTech shuttle in South Florida, managing a four-mile route in West Palm Beach and a one-mile route in Boca Raton using its remote monitoring technology. | Credit: GuidentCalifornia is redefining the regulatory landscape for dri
Related Special Topic Recommendations
Comments (0)
0/500
Microsoft recently removed dozens of open-source repositories from GitHub after hackers infiltrated them and injected malicious code designed to steal user passwords. The move prompted strong reactions across the developer community.

Precision Targeting of AI Developers
Security firm Cloudsmith and malware analysis platform OpenSourceMalware were the first to detect the anomaly. Reports indicate that the affected projects were primarily tied to Microsoft Azure cloud services and several popular AI development tools, including components associated with AI coding applications like Claude Code, the Gemini CLI, and VS Code.
The attackers executed targeted software supply chain attacks by embedding malicious code into these tools. When developers opened the compromised tools locally through AI coding applications, the malware ran silently, attempting to steal local passwords and other sensitive credentials.
Emergency Removal for Risk Investigation
Microsoft later confirmed that, as a security measure, it had temporarily taken down at least 70 related code repositories while investigating potential malicious content. Some have since been restored after security reviews, while others remain disabled due to ongoing risks.
During the internal investigation, Microsoft sent security notifications to a small number of customers who may have downloaded affected content. Despite Microsoft’s strong security resources and protections, this marks the second time in recent weeks that its open-source projects have been compromised—highlighting the serious security challenges facing the current AI development ecosystem.
DeepMind CEO Hassabis: I sleep six hours a day, usually feel energetic around 1 a.m.
Fortune recently featured an interview with Demis Hassabis, CEO of Google DeepMind, revealing his unconventional approach to rest and productivity. Hassabis disclosed that he sleeps very little, structuring his waking hours into two distinct work blo
OpenAI, Anthropic Vie for Market Share Despite Revenue Shortfalls
Despite recent reports suggesting OpenAI missed revenue targets, creating pressure on tech stocks this Tuesday, private AI lab investors remain resilient. Seasoned backers have confirmed they will not reduce investment despite negative media coverage











