Case · DiggingBeagle record

Microsoft open-source repositories delivered credential-stealing malware into AI developer workflows

Microsoft temporarily removed dozens of compromised GitHub repositories after attackers injected credential-stealing malware into open-source tools used in Azure and AI-development workflows. TechCrunch reported at least 70 repositories disabled; Microsoft said a small number of customers who may have pulled affected content were notified.

First seen
Jun 8, 2026
Case kind
incident
AI role
AGAINST AI
Claims
6

Reconstruction

Treat as a software supply-chain compromise intersecting AI developer tooling, not as an AI-agent attack.

Claims & evidence

reported findingsupported

TechCrunch observed at least 70 Microsoft GitHub repositories disabled during the investigation, while Microsoft said only a small number of customers were notified as potentially having pulled affected content.

reported findingunreviewed

The public reporting did not establish how many developers downloaded malicious content or whether downstream credential theft produced confirmed secondary compromises.

reported findingsupported

Affected tools were used by developers inside AI coding environments including Claude Code and Gemini CLI; the AI tools were an execution context/target surface, not autonomous attackers.

reported findingsupported

The malicious code was planted in open-source projects and could steal passwords and other credentials when affected tools were opened through AI coding environments including Claude Code, Gemini CLI and VS Code.

reported findingcontested

The June incident included a reported re-compromise of Microsoft's Durable Task project after a related compromise had been identified in May, raising a persistence or repeat-access question.

Scope: TechCrunch attributes the re-compromise characterization to OpenSourceMalware; Microsoft did not publicly establish whether the same actor retained access.

Implications

What remains unknown

  • Number of affected developers and downstream systems remains undisclosed.
  • Public reporting does not establish attacker identity or whether the May and June compromises were the same intrusion.

Cite this record

DiggingBeagle. “Microsoft open-source repositories delivered credential-stealing malware into AI developer workflows.” First seen Jun 8, 2026. https://diggingbeagle.com/cases/microsoft-open-source-repositories-delivered-credential-stealing-malware-into-ai/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.