Home
Microsoft open source project hacked, AI development tools infected with password-stealing malware
Microsoft recently removed dozens of open-source repositories from GitHub after hackers infiltrated them and injected malicious code designed to steal user passwords. The move prompted strong reactions across the developer community.

Precision Targeting of AI Developers
Security firm Cloudsmith and malware analysis platform OpenSourceMalware were the first to detect the anomaly. Reports indicate that the affected projects were primarily tied to Microsoft Azure cloud services and several popular AI development tools, including components associated with AI coding applications like Claude Code, the Gemini CLI, and VS Code.
The attackers executed targeted software supply chain attacks by embedding malicious code into these tools. When developers opened the compromised tools locally through AI coding applications, the malware ran silently, attempting to steal local passwords and other sensitive credentials.
Emergency Removal for Risk Investigation
Microsoft later confirmed that, as a security measure, it had temporarily taken down at least 70 related code repositories while investigating potential malicious content. Some have since been restored after security reviews, while others remain disabled due to ongoing risks.
During the internal investigation, Microsoft sent security notifications to a small number of customers who may have downloaded affected content. Despite Microsoft’s strong security resources and protections, this marks the second time in recent weeks that its open-source projects have been compromised—highlighting the serious security challenges facing the current AI development ecosystem.
Related article
ByteDance Boosts Core AI Incentives as Doubao Surges 14.6%
ByteDance recently convened a DouBao equity briefing to unveil fresh incentive policies for staff involved in the DouBao division. The strike price for DouBao shares has been lifted from $14.85 in June 2026 to $17.02, marking an approximate 14.6% inc
MiniMax Unveils 10x Team Program to Incentivize Global AI Experts
MiniMax (Xiyu Technology), the General Artificial Intelligence Lab, has officially launched "10x Team," a global talent collaboration initiative. This program aims to recruit top experts across industries to explore the deep application of large mode
South Korea Breaks Ground on National AI Computing Center, Investing 2.5 Trillion Won with 2028 Target
South Korean outlet EtNews reports that groundbreaking for the Korea AI Computing Center (KOACC) took place on August 3 at the Solar City data center park in Sunan, Jeollanam-do. Backed by a total investment of 2.5 trillion KRW (roughly 11.838 billio
Related Special Topic Recommendations
Comments (0)
0/500
Microsoft recently removed dozens of open-source repositories from GitHub after hackers infiltrated them and injected malicious code designed to steal user passwords. The move prompted strong reactions across the developer community.

Precision Targeting of AI Developers
Security firm Cloudsmith and malware analysis platform OpenSourceMalware were the first to detect the anomaly. Reports indicate that the affected projects were primarily tied to Microsoft Azure cloud services and several popular AI development tools, including components associated with AI coding applications like Claude Code, the Gemini CLI, and VS Code.
The attackers executed targeted software supply chain attacks by embedding malicious code into these tools. When developers opened the compromised tools locally through AI coding applications, the malware ran silently, attempting to steal local passwords and other sensitive credentials.
Emergency Removal for Risk Investigation
Microsoft later confirmed that, as a security measure, it had temporarily taken down at least 70 related code repositories while investigating potential malicious content. Some have since been restored after security reviews, while others remain disabled due to ongoing risks.
During the internal investigation, Microsoft sent security notifications to a small number of customers who may have downloaded affected content. Despite Microsoft’s strong security resources and protections, this marks the second time in recent weeks that its open-source projects have been compromised—highlighting the serious security challenges facing the current AI development ecosystem.
ByteDance Boosts Core AI Incentives as Doubao Surges 14.6%
ByteDance recently convened a DouBao equity briefing to unveil fresh incentive policies for staff involved in the DouBao division. The strike price for DouBao shares has been lifted from $14.85 in June 2026 to $17.02, marking an approximate 14.6% inc
MiniMax Unveils 10x Team Program to Incentivize Global AI Experts
MiniMax (Xiyu Technology), the General Artificial Intelligence Lab, has officially launched "10x Team," a global talent collaboration initiative. This program aims to recruit top experts across industries to explore the deep application of large mode
South Korea Breaks Ground on National AI Computing Center, Investing 2.5 Trillion Won with 2028 Target
South Korean outlet EtNews reports that groundbreaking for the Korea AI Computing Center (KOACC) took place on August 3 at the Solar City data center park in Sunan, Jeollanam-do. Backed by a total investment of 2.5 trillion KRW (roughly 11.838 billio











