Home
Microsoft warns of supply chain attack on dozens of open source AI tools, with developer credentials compromised
Microsoft temporarily restricted access to at least 70 open-source projects on GitHub after a cyberattack. Hackers injected malicious code via a supply chain attack to steal passwords and credentials when users ran the compromised tools in AI coding apps like Claude Code, Gemini CLI, and VS Code.

Microsoft spokesperson Ben Hope confirmed that affected repositories were temporarily removed during the investigation, with some code restored after review. This marks the second known security breach involving Microsoft's open-source projects in recent weeks. In mid-May, its Durable Task tool was previously hacked, with security agency OpenSourceMalware noting this as a "second invasion" of the project.
As large AI models and open-source ecosystems integrate, this intrusion into a major resource library sounds a safety alarm. With the rapid rise of AI coding assistants, the open-source supply chain has become the new main battlefield for cyber warfare. Building more resilient code review and security protection mechanisms is a common challenge that tech giants must address in the AI era.
Related article
ByteDance’s Seed launches global campus drive, offering virtual shares to win top large model talent
In the competitive landscape of large language models, securing top-tier talent remains the most critical strategic asset.On April 1st, ByteDance announced the launch of its Seed global campus recruitment initiative, part of its large model talent de
Suno to Watermark Songs Amid Legal Battles
Suno, the platform enabling users to generate AI-created music, has unveiled new features to label platform-produced tracks, restrict downloads, and update community standards to curb unauthorized replicas. These updates arrive as Suno confronts mult
Musk Admits Grok Build Leaked User Code, Promises to Erase All Historical Data
Elon Musk directly addressed the privacy controversy surrounding Grok Build, beginning with a simple "True" to confirm the incident's validity. He pledged that all user data previously uploaded to SpaceXAI would be permanently erased, stating, "not a
Related Special Topic Recommendations
Comments (0)
0/500
Microsoft temporarily restricted access to at least 70 open-source projects on GitHub after a cyberattack. Hackers injected malicious code via a supply chain attack to steal passwords and credentials when users ran the compromised tools in AI coding apps like Claude Code, Gemini CLI, and VS Code.

Microsoft spokesperson Ben Hope confirmed that affected repositories were temporarily removed during the investigation, with some code restored after review. This marks the second known security breach involving Microsoft's open-source projects in recent weeks. In mid-May, its Durable Task tool was previously hacked, with security agency OpenSourceMalware noting this as a "second invasion" of the project.
As large AI models and open-source ecosystems integrate, this intrusion into a major resource library sounds a safety alarm. With the rapid rise of AI coding assistants, the open-source supply chain has become the new main battlefield for cyber warfare. Building more resilient code review and security protection mechanisms is a common challenge that tech giants must address in the AI era.
ByteDance’s Seed launches global campus drive, offering virtual shares to win top large model talent
In the competitive landscape of large language models, securing top-tier talent remains the most critical strategic asset.On April 1st, ByteDance announced the launch of its Seed global campus recruitment initiative, part of its large model talent de
Suno to Watermark Songs Amid Legal Battles
Suno, the platform enabling users to generate AI-created music, has unveiled new features to label platform-produced tracks, restrict downloads, and update community standards to curb unauthorized replicas. These updates arrive as Suno confronts mult
Musk Admits Grok Build Leaked User Code, Promises to Erase All Historical Data
Elon Musk directly addressed the privacy controversy surrounding Grok Build, beginning with a simple "True" to confirm the incident's validity. He pledged that all user data previously uploaded to SpaceXAI would be permanently erased, stating, "not a











