TechDogs-"Microsoft Pulls Open-Source GitHub Repos After Malware Targets AI Developers’ Passwords"

Cyber Security

Microsoft Pulls Open-Source GitHub Repos After Malware Targets AI Developers’ Passwords

By Utkarsh Hiwale

Updated on Tue, Jun 9, 2026

Overall Rating

Microsoft has taken dozens of open-source GitHub repositories offline after researchers found malware that could steal passwords and credentials when developers opened compromised projects inside AI coding tools and developer environments.


TL;DR

 
  • Microsoft temporarily removed multiple open-source repositories while investigating malicious content.
  • Researchers said the attack targeted developers using tools such as Claude Code, Gemini CLI, Cursor, and VS Code.
  • StepSecurity said GitHub disabled 73 repositories across four Microsoft GitHub organizations.
  • Microsoft said it notified a small number of customers who may have pulled affected content.


Microsoft has temporarily cut off access to several open-source projects hosted on GitHub after reports that attackers injected credential-stealing malware into some of its repositories.

Source


The affected projects were related to Microsoft Azure, Azure Functions, Durable Task, and AI coding workflows used by developers. According to TechCrunch, the malware was designed to steal passwords and sensitive credentials when users opened compromised tools inside AI coding apps such as Claude Code, Gemini CLI, and VS Code.


Microsoft confirmed the action through spokesperson Ben Hope, who told TechCrunch that the company “temporarily removed some repositories” while investigating potentially malicious content. He added that “some of these repos have been restored after review,” while others could remain offline as the investigation continues.


Security firm StepSecurity said the incident was linked to the Miasma worm campaign and reached Microsoft’s Azure GitHub organizations on June 5, 2026. According to its analysis, GitHub disabled 73 repositories across four Microsoft GitHub organizations after a malicious commit was pushed to Azure/durabletask using a previously compromised contributor account.


The malicious files were not traditional source-code changes. StepSecurity said the commit added configuration files that triggered a credential-harvesting payload when a developer opened the repository in Claude Code, Gemini CLI, Cursor, or VS Code.


This made the attack particularly concerning because cloning the repository was safe, but opening it in certain tools could trigger malicious behavior.


The attack also appeared to avoid routine detection methods. StepSecurity said the commit used a misleading message, added no source-code modifications, included a “skip ci” flag, and was backdated to 2020, even though it was pushed in 2026.


AI coding tools often read project files, execute setup commands, and interact with developer environments. That makes them powerful, but it also means a malicious configuration file can become a dangerous entry point if the tool trusts project-level instructions too easily.


StepSecurity noted that the attack shifted from traditional package-install malware to “execute on folder open” behavior. In simpler terms, the threat did not need to wait for a package manager install step. It targeted the moment a developer opened the project in an AI-assisted coding environment.


Techzine reported that developers using GitHub Actions from affected repositories were also disrupted, with some Azure/functions-action users unable to run deployment workflows while repositories were offline. Microsoft advised temporary alternatives such as Azure CLI, Azure DevOps Pipelines, Azure Pipelines, VS Code, and Zip Deploy.


This may not be Microsoft’s first related open-source security incident in recent weeks.


StepSecurity said that, in May, three malicious versions of Microsoft’s durabletask PyPI package were uploaded in a 35-minute window and were designed to steal secrets from AWS, Azure, GCP, Kubernetes, and more than 90 developer-tool configurations.

 

Topics for more insights: 



The firm said the attacker bypassed the repository’s CI/CD pipeline and uploaded directly to PyPI using a compromised publishing token.


TechCrunch also reported that OpenSourceMalware described the latest incident as a possible re-compromise of Durable Task, though Microsoft has not publicly confirmed whether the two incidents are connected.


For now, Microsoft said it has notified a small number of customers who may have downloaded content from affected repositories. The company has not disclosed how many developers were affected or how the attacker initially gained access.

First published on Tue, Jun 9, 2026

Liked what you read? That’s only the tip of the tech iceberg!

Explore our vast collection of tech articles including introductory guides, product reviews, trends and more, stay up to date with the latest news, relish thought-provoking interviews and the hottest AI blogs, and tickle your funny bone with hilarious tech memes!

Plus, get access to branded insights from industry-leading global brands through informative white papers, engaging case studies, in-depth reports, enlightening videos and exciting events and webinars.

Dive into TechDogs' treasure trove today and Know Your World of technology like never before!

Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.

Loading comments...

  • Dark
  • Light