tech
For the 2nd time in weeks, Microsoft packages laced with credential stealer
73 packages run self-replicating stealer as soon as they’re opened by an AI agent.

TL;DR
- 73 Microsoft-owned open source packages were compromised with credential-stealing code.
- The malware, Miasma, is triggered when packages are opened in AI coding agents.
- This is the second supply-chain attack on a Microsoft repository in recent months.
- The attack harvests credentials for AWS, Azure, GCP, Kubernetes, and other developer tools.
- Miasma bypasses traditional detection methods by generating unique encrypted payloads and using legitimate OIDC tokens.
- Developers are urged to assume compromise and investigate their systems thoroughly.