Apps & Consumer
Microsoft pulls 70+ GitHub projects after malware breach
Microsoft has apparently disabled at least 70 open-source projects on GitHub following a suspected breach involving password-stealing malware targeting AI development tools.
Microsoft has cut off access to at least 70 of its open-source projects hosted on GitHub. The company disabled the repositories due to a suspected breach involving password-stealing malware, where hackers apparently breached the projects. Visitors attempting to access the affected project pages on GitHub, the code-hosting platform owned by Microsoft, were met with a message stating that access had been disabled by GitHub staff due to a terms of service violation. Many of these projects relate to Microsoft’s cloud service Azure and other tools used by developers to code with AI development apps, including Claude Code, Gemini, and VS Code.
According to security firm Cloudsmith and the community-driven malware analysis site OpenSourceMalware, which were among the first to flag the hack, the malware allowed hackers to steal users’ passwords and other sensitive credentials. This occurred when developers opened the compromised tools in their AI coding apps. It is not immediately known how many users downloaded the affected tools before they were taken offline.
Microsoft confirmed it pulled the repositories following an initial report by media outlet 404 Media. Microsoft spokesperson Ben Hope confirmed the action, stating that the company “temporarily removed some repositories as we investigated potential malicious content.” Hope added that some of these repositories have been restored after review, while others may remain offline as work continues. As part of the investigation, Microsoft has notified a small number of customers who may have pulled down content from the affected repositories. The company did not immediately provide the specific number of affected customers.
This incident serves as an example of a supply chain attack, which is a cyberattack that targets code used in many software products to compromise downstream users. This marks a follow-up to a previous breach. In mid-May, Microsoft’s open-source project Durable Task was hacked. According to OpenSourceMalware, the latest incident is a “re-compromise” of the Durable Task project, suggesting that Microsoft may not have eradicated the hackers on its first attempt or that a new breach has occurred.
Why it matters
This incident represents a significant supply chain attack against Microsoft’s open-source ecosystem, underscoring the persistent security risks for developers integrating AI coding tools into their workflows.