Microsoft has cut off access to more than 70 of its open-source projects on GitHub after attackers laced them with credential-stealing malware aimed squarely at AI developers. The breach, reported by TechCrunch and first surfaced by 404 Media, hit tools tied to the company's Azure cloud platform and to utilities developers run alongside AI coding apps such as Claude Code, Gemini's command-line interface, and VS Code.
How the attack worked
According to the security firm Cloudsmith and the community tracker OpenSourceMalware, the malware harvested passwords and other sensitive credentials the moment a compromised tool was opened inside one of those AI coding environments. The strain has been named Miasma, a self-replicating credential stealer built on the Mini Shai-Hulud codebase that a group calling itself TeamPCP released into the open.
This is the textbook shape of a supply-chain attack. Rather than going after developers one by one, the attackers poisoned code that thousands of projects pull in automatically. Compromise the dependency once, and the infection rides along into every product that trusts it. Developers are an especially rich target, since their machines often hold keys to cloud systems and to large stores of customer data.
A repeat offence
Microsoft confirmed the action through spokesperson Ben Hope, who said the company had "temporarily removed some repositories as we investigated potential malicious content." Some have already been restored after review, while others remain offline pending further work.
The detail that should give people pause is that this is not the first time. OpenSourceMalware describes the incident as a re-compromise of Durable Task, a Microsoft project for building durable apps that was breached back in mid-May. Either the original intruders were never fully cleared out, or a fresh crew walked back in through the same door. Neither reading is reassuring.
The broader lesson keeps repeating itself. As AI coding assistants pull in ever more third-party tooling, the attack surface grows with them, and the trust developers place in a familiar repository name is exactly what these campaigns are built to exploit. Rotating any credentials touched by an affected tool is the sensible first move.
Sources
- i. techcrunch.com
- ii. gigazine.net
- iii. contentbuffer.com
- iv. parameter.io
Commentarii · 0