
Microsoft pulls dozens of open source repos after password-stealing hack
Microsoft has disabled at least 70 open source projects on GitHub while it investigates malware that stole credentials from developers using AI coding tools such as Claude Code and Gemini CLI.
Microsoft has cut off access to dozens of its open source projects hosted on GitHub while it investigates how hackers breached them and injected password-stealing malware into the code.
What was compromised
Many of the affected projects relate to Microsoft's Azure cloud service and to tools that developers use to code with AI assistants, including Claude Code, Gemini's command-line interface and VS Code. According to the security firm Cloudsmith and the community malware-analysis site OpenSourceMalware, which were among the first to flag the incident, the malware let attackers steal passwords and other sensitive credentials when a user opened a compromised tool inside an AI coding app. It is not yet clear how many people downloaded the affected tools.
Microsoft's response
Microsoft confirmed that it had pulled the repositories, a move first reported by 404 Media. “We temporarily removed some repositories as we investigated potential malicious content,” company spokesperson Ben Hope said. “Some of these repos have been restored after review, while others may remain offline while work continues.”
Hope added that the company had notified “a small number of customers who may have pulled down content from the affected repositories” and said Microsoft would keep investigating and reach out directly through its support channels if any further action is required. The company did not say how many customers were affected. On GitHub, which Microsoft owns, at least 70 of the company's projects displayed a notice that access had been disabled by GitHub staff for a violation of the site's terms of service.
A repeat of an earlier breach
Supply chain attacks of this kind target code that is widely reused across software products or used by a specific class of users — such as developers with access to cloud systems and large volumes of customer data. Attacks on individual open source maintainers are common; a breach at a company of Microsoft's size is not. This is Microsoft's second known compromise of open source projects in a matter of weeks. In mid-May, researchers reported that Durable Task, an open source tool for building apps, had been hacked. OpenSourceMalware described the latest incident as a “re-compromise” of that project, suggesting either that the hackers were not fully removed the first time or that a separate intrusion took place.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.