404 Media · Joseph Cox ·

Microsoft has shut down 70+ of its own repositories on GitHub after hackers pushed malware that would steal credentials from users of AI coding agents

Microsoft took the highly unusual step of shutting down more than 70 of its own GitHub repositories after hackers pushed malware …

In this story GitHub Microsoft
Microsoft has shut down 70+ of its own repositories on GitHub after hackers pushed malware that would steal credentials from users of AI coding agents

Lead Source

How this story grew

Coverage · 0 Discussion · 0
Jun 8Jun 9

More

OpenSourceMalware.com: OpenSourceMalware.com
Step Security Blog: Step Security Blog
Ars Technica: Ars Technica
TechCrunch: TechCrunch
Runtime: Runtime
The Hacker News: The Hacker News
The New Stack: The New Stack

Discussion

TechSnif Coverage

Microsoft Nukes 70+ Own GitHub Repos After Malware Attack

Hackers injected credential-stealing malware targeting AI coding agent users into Microsoft's own repositories.

Microsoft just torched more than 70 of its own GitHub repositories. The reason? Hackers managed to push malware into them designed to steal credentials from people using AI coding agents.

It's a remarkably unusual move. Microsoft — which owns GitHub — had to shut down its own repos to contain the threat. The attack specifically targeted users of AI-powered coding tools, exploiting the trust developers place in official Microsoft repositories.

The incident highlights a growing attack surface as AI coding assistants become standard developer tools. If hackers can poison the repos these agents pull from, they can compromise entire development workflows without touching the end user directly.

The takeaway is brutal: even first-party repos from the platform owner aren't safe. The supply chain attack vector just got a lot more uncomfortable for anyone leaning on AI agents to write code.