For the 2nd time in weeks, Microsoft packages laced with credential stealer

Microsoft-owned GitHub repositories were compromised for the second time in weeks, with 73 packages found to contain credential-stealing malware. The malicious code is designed to trigger when accessed by AI coding agents, potentially exposing sensitive cloud and developer credentials.
Why it matters
This incident underscores the growing security risks in software supply chains, particularly as developers increasingly integrate AI agents into their workflows.
THE HACK THAT KEEPS ON HACKING For the 2nd time in weeks, Microsoft packages laced with credential stealer 73 packages run self-replicating stealer as soon as they re opened by an AI agent.
The report focuses on technical facts and security implications without political or ideological framing.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in