Microsoft disabled 70+ of its repos on GitHub, including Azure-related tools like azure-functions-host, after hackers added credential-stealing malware to them
Microsoft has cut off access to dozens of its open source projects hosted on GitHub as it investigates how hackers apparently breached …
Lead Source
How this story grew
More
Discussion
TechSnif Coverage
Microsoft Kills 70+ GitHub Repos After Hackers Plant Malware
Microsoft yanked access to dozens of its own open source projects on GitHub after attackers injected credential-stealing malware.
Microsoft just hit the kill switch on more than 70 of its own GitHub repositories. The reason? Hackers managed to slip credential-stealing malware into them.
The affected repos include critical Azure-related tools like azure-functions-host — the kind of infrastructure countless developers depend on daily. Microsoft disabled access while it investigates how attackers apparently breached its open source projects.
The scope is significant. We're not talking about obscure side projects. These are core developer tools tied to Microsoft's cloud platform. Anyone who pulled code from these repos during the compromise window could potentially have exposed their credentials.
Microsoft is actively investigating the breach. Details on exactly how the hackers gained write access to the repositories remain unclear. The company hasn't disclosed a timeline for restoring access to the disabled projects.
For now, developers relying on these tools are stuck waiting.