73 official Microsoft open-source packages were found infected with credential-stealing malware. The self-replicating stealer executes as soon as AI coding agents open the packages.
Last week, 73 official Microsoft open-source packages were found infected with credential-stealing malware. The self-replicating stealer executes as soon as AI coding agents open the packages. GitHub blocked the packages citing 'terms of service violation', and Microsoft only acknowledged possible infection on Monday.
This is the second supply-chain attack on Microsoft's official repository account in two months. In May, Microsoft's durabletask Python SDK on PyPI was compromised. The attack, linked to threat actor TeamPCP, used stolen Microsoft publishing credentials to bypass the build pipeline. The malware 'Miasma' steals credentials from AWS, Azure, GCP, Kubernetes, password managers, and over 90 developer tools, then spreads laterally through cloud infrastructure.
This incident highlights the vulnerability of official repository accounts to credential theft and the heightened risk of supply-chain attacks in AI coding agent environments. Microsoft's delayed response and GitHub's vague action (terms of service violation) erode developer trust. The technique of stealing OIDC tokens to bypass SLSA provenance attestation could become a template for future attacks.