Microsoft Pulls Dozens of GitHub Repos After Hack

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Microsoft temporarily removed dozens of its open‑source repositories from GitHub after discovering password‑stealing malware injected into the code.
- Cloudsmith and OpenSourceMalware were among the first to flag the breach, noting the malware could capture passwords and credentials when developers opened the compromised tools in AI coding apps.
- GitHub displayed a message that access to at least 70 Microsoft repositories had been disabled due to a violation of its terms of service.
- Microsoft notified a small number of customers who may have downloaded the infected projects and said it would reach out directly if further action is required.
- Durable Task, a Microsoft open‑source project, appears to have been re‑compromised, indicating the earlier May breach may not have been fully eradicated.
- Azure‑related AI development tools such as Claude Code, Gemini CLI, and VS Code were among the compromised projects, illustrating a supply‑chain attack that could expose developers’ credentials.
Why it matters: Developers using Microsoft’s Azure‑linked AI tools now risk credential theft, while the company must devote resources to remediate the breach and restore trust in its open‑source ecosystem. The incident shows that even major cloud providers can fall victim to supply‑chain attacks, raising security concerns for the broader developer community.


