tech

Microsoft's open source tools were hacked to steal passwords of AI developers

Microsoft shut down dozens of GitHub code repositories for Azure and AI coding tools after a reported hack.

Microsoft's open source tools were hacked to steal passwords of AI developers

TL;DR

  • Microsoft has disabled dozens of open-source projects on GitHub over concerns of malicious content.
  • Hackers reportedly injected password-stealing malware into code for Azure and AI development tools.
  • The affected tools include those used for Claude Code, Gemini's CLI, and VS Code.
  • Microsoft is investigating the breach and has temporarily removed repositories, with some being restored after review.
  • This incident is characterized as a "supply chain" attack, targeting widely used code to compromise numerous users.
  • This marks Microsoft's second known breach of its open-source projects in recent weeks.