tech

For the 2nd time in weeks, Microsoft packages laced with credential stealer

73 packages run self-replicating stealer as soon as they’re opened by an AI agent.

For the 2nd time in weeks, Microsoft packages laced with credential stealer

TL;DR

  • 73 Microsoft-owned open source packages were compromised with credential-stealing code.
  • The malware, Miasma, is triggered when packages are opened in AI coding agents.
  • This is the second supply-chain attack on a Microsoft repository in recent months.
  • The attack harvests credentials for AWS, Azure, GCP, Kubernetes, and other developer tools.
  • Miasma bypasses traditional detection methods by generating unique encrypted payloads and using legitimate OIDC tokens.
  • Developers are urged to assume compromise and investigate their systems thoroughly.