Microsoft, a tech giant, recently took down dozens of open-source project repositories on the GitHub platform. The incident originated from hackers successfully infiltrating these projects and maliciously injecting code designed to steal user passwords, causing strong reactions in the development community.

image.png

Targeting AI Developers Precisely

Security company Cloudsmith and malware analysis website OpenSourceMalware were the first to detect this anomaly. Reports indicate that the affected projects mainly focused on Microsoft Azure cloud services and a series of popular AI development tools, including components related to AI coding applications such as Claude Code, Gemini command-line interface, and VS Code.

Hackers implemented targeted "software supply chain attacks" by embedding malicious code into these tools. Once developers opened these tampered tools through AI coding applications locally, the malicious program would run silently, attempting to steal users' local passwords and other sensitive credentials.

Emergency Removal for Risk Investigation

Microsoft confirmed later that, for security protection, the company had temporarily removed at least 70 related code repositories during the investigation of potential malicious content. Currently, some repositories have been restored online after security checks, while others still remain disabled due to risks.

During the internal investigation, Microsoft has issued security notifications to a small number of customers who may have pulled affected content. Although Microsoft has high security resources and protective capabilities, this is the second time in recent weeks that its open-source projects have been exposed to hacker infiltration, highlighting the serious security challenges facing the current AI development ecosystem.