PulseAugur
EN
LIVE 20:04:32

Microsoft packages compromised twice with credential-stealing AI malware

Microsoft's official open-source packages have been compromised for the second time in recent weeks, with malicious code designed to steal credentials being injected into 73 packages. This code activates when developers use AI coding agents to open the packages, potentially compromising systems by stealing tokens for cloud providers like AWS, Azure, and GCP, as well as password managers and developer tools. The attack, linked to threat actor TeamPCP and using malware known as Miasma, bypasses repository build pipelines by leveraging legitimate Microsoft OIDC tokens. AI

IMPACT Compromised AI development tools and packages pose a significant risk to the security of AI projects and infrastructure.

RANK_REASON This cluster describes a security incident involving compromised software packages, not a new AI model release or core AI research.

Read on Ars Technica — AI →

AI-generated summary · Google Gemini · from 2 sources. How we write summaries →

Microsoft packages compromised twice with credential-stealing AI malware

COVERAGE [2]

  1. Ars Technica — AI TIER_1 English(EN) · Dan Goodin ·

    For the 2nd time in weeks, Microsoft packages laced with credential stealer

    73 packages run self-replicating stealer as soon as they're opened by an AI agent.

  2. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    For the second time in weeks, Microsoft packages have been found laced with credential-stealing code designed to activate when developers open them in AI coding

    For the second time in weeks, Microsoft packages have been found laced with credential-stealing code designed to activate when developers open them in AI coding agents. 73 packages were blocked on GitHub, executing a payload that steals credentials from AWS, Azure, GCP, Kubernete…