• About
  • Advertise
  • Careers
  • Contact
  • Local Guide
Tuesday, June 9, 2026
No Result
View All Result
NEWSLETTER
The Seattle Today
  • Home
  • Arts & Culture
  • Business
  • Politics
  • Technology
  • Housing
  • International
  • National
  • Local Guide
  • Home
  • Arts & Culture
  • Business
  • Politics
  • Technology
  • Housing
  • International
  • National
  • Local Guide
No Result
View All Result
The Seattle Today
No Result
View All Result
Home Business

Microsoft Pulls Dozens of GitHub Projects After Hackers Inject Password-Stealing Malware Into Azure and AI Developer Tools

by Favour Bitrus
June 9, 2026
in Business, Tech
0 0
0
Microsoft Pulls Dozens of GitHub Projects After Hackers Inject Password-Stealing Malware Into Azure and AI Developer Tools

Picture Credit: BoliviaInteligente

0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Microsoft has cut off access to at least 70 of its open source projects hosted on GitHub after hackers apparently breached the repositories and injected malware designed to steal passwords and sensitive credentials from developers using popular AI coding tools including Claude Code, Gemini’s command line interface, and VS Code.

The affected projects are primarily connected to Microsoft’s Azure cloud services and developer tools used alongside AI applications. According to security firm Cloudsmith and community-driven malware analysis site OpenSourceMalware, which were among the first to identify the breach, the malware activated when users opened the compromised tools within their AI coding environments, allowing attackers to harvest passwords and other credentials stored on their machines.

At least 70 Microsoft projects on GitHub have been disabled. Users attempting to access the affected repository pages encounter a message stating that access has been disabled by GitHub staff due to a violation of GitHub’s terms of service. GitHub is owned by Microsoft.

Microsoft spokesperson Ben Hope confirmed the repositories had been taken down. “We have temporarily removed some repositories as we investigated potential malicious content,” Hope said. “Some of these repos have been restored after review, while others may remain offline while work continues.” Hope added that the company notified a small number of customers who may have downloaded content from the affected repositories and said Microsoft would reach out directly through established support channels if further action is required. The company did not disclose the specific number of customers affected.

The breach is the second known incident of this kind involving Microsoft’s open source projects in recent weeks. In mid-May, security researchers reported that Microsoft’s Durable Task project, a tool that helps developers build applications, had been compromised in a similar manner. OpenSourceMalware described the latest incident as a possible re-compromise of the same project, raising the question of whether Microsoft fully eradicated the attackers following the first breach or whether an entirely new intrusion has occurred.

The attack is an example of what security researchers call a supply chain attack, in which hackers target widely used code rather than individual systems, allowing them to reach a large number of users at once. Developers who work with Azure and AI tools often have access to cloud infrastructure and sensitive customer data, making them high-value targets. While supply chain attacks against individual open source maintainers have become increasingly common, it is unusual for a company of Microsoft’s scale and security resources to be compromised in this way, let alone twice within a matter of weeks.

The number of users who may have downloaded the affected code before the repositories were pulled has not been confirmed.

Tags: Azure open source supply chain attackMicrosoft Claude Code Gemini malware 2026Microsoft GitHub malware breach
Favour Bitrus

Favour Bitrus

Recommended

Picture Credit: the Seattle Times

Washington Attorney General Co-Leads Multi-State Lawsuit Challenging Trump’s Mail-In Voting Executive Order

2 months ago
Picture Credit: King5 News

Lawsuit Claims Unsafe Crossing Design and Malfunctioning Alert System Led to Train Striking Wheelchair User in Seattle

7 months ago

Popular News

  • Federal Judge Strikes Down Trump Administration’s $100,000 H-1B Visa Fee in Win for Seattle Tech Employers

    Federal Judge Strikes Down Trump Administration’s $100,000 H-1B Visa Fee in Win for Seattle Tech Employers

    0 shares
    Share 0 Tweet 0
  • Renton Police Deploy Real-Time 56-Language Translation on Body Cameras Ahead of FIFA World Cup

    0 shares
    Share 0 Tweet 0
  • Two Seattle Council Members Signal Concerns About Mayor Wilson’s Transit Tax Proposal Before Hearings Begin

    0 shares
    Share 0 Tweet 0
  • Seattle Council Members Say They Were Unaware of Any Specific World Cup Threat as CCTV Debate Intensifies

    0 shares
    Share 0 Tweet 0
  • 2.9 Magnitude Earthquake Strikes Near Oak Harbor Late Sunday Night

    0 shares
    Share 0 Tweet 0

Connect with us

  • About
  • Advertise
  • Careers
  • Contact
  • Local Guide
Contact: info@theseattletoday.com
Send Us a News Tip: info@theseattletoday.com
Advertising & Partnership Inquiries: info@theseattletoday.com

Follow us on Instagram | Facebook | X

Join thousands of Seattle locals who follow our stories every week.

© 2025 Seattle Today - Seattle’s premier source for breaking and exclusive news.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Arts & Culture
  • Business
  • Politics
  • Technology
  • Housing
  • International
  • National
  • Local Guide

© 2025 Seattle Today - Seattle’s premier source for breaking and exclusive news.