Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Peterborough residents urged to avoid fireworks in heat spell

    August 13, 2026

    Maersk shares jump after shipping giant beats estimates, hikes outlook

    August 13, 2026

    Trump sued over “brazen” scheme to sell Truth Social API access for $100K a month

    August 13, 2026
    Facebook X (Twitter) Instagram
    Addison Markets
    • Home
    • USA
    • Europe
    • Business
    • Investing
    • Tech
    • Politics
    • Contact Us
    Addison Markets
    Home»Tech»For the 2nd time in weeks, Microsoft packages laced with credential stealer
    Tech

    For the 2nd time in weeks, Microsoft packages laced with credential stealer

    franperez66q@protonmail.comBy franperez66q@protonmail.comJune 9, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email



    Dozens of cryptographically verified open source packages from Microsoft were compromised late last week to add advanced credential-stealing code that was triggered when developers opened them in AI coding agents.

    In all, multiple researchers said, 73 packages were flagged as malicious when automated systems on GitHub blocked them on the platform. Rather than noting they are malicious—and that developers who used AI agents to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub’s terms of service.” The text went on to encourage the package owner to contact GitHub.

    Devs: Assume compromise and proceed accordingly

    It wasn’t until Monday that Microsoft even raised the possibility the packages were infected. In an email, the company stated: “We have temporarily removed some repositories as we investigate potential malicious content.”

    The incident is the second supply-chain attack in as many months to breach an official Microsoft repository account. In mid May, the firm StepSecurity documented the compromise of Microsoft’s durabletask Python SDK on PyPI. The package is a framework for building fault-tolerant workflows and orchestrations to automate distributed transactions and other workflows. It receives 400,000 downloads per month.

    The compromise packages executed a 28 KB payload that steals credentials from AWS, Azure, GCP, Kubernetes, password managers, and over 90 developer tool configurations. It then spreads laterally through cloud infrastructures to infect other developer machines. The attack, which has been linked to a threat actor tracked as TeamPCP, poisoned the durabletask package after compromising Microsoft credentials for publishing the package. The technique allows attackers to bypass the repository’s build pipeline entirely.

    The malware used in the attack is tracked as Miasma. It’s essentially a clone of TeamPCP’s Mini Shai-Hulud toolkit, which the threat actor open-sourced recently. Security firm Cloudsmith said the malware harvests OIDC (OpenID-Connect) token credentials that are used in SLSA (Supply-chain Levels for Software Artifacts) provenance attestation, a method for providing cryptographically signed guarantees of a software’s integrity.

    As was the case in the May compromise of Microsoft’s durabletask, the one last week made use of the functionality to steal a legitimate Microsoft OIDC token. It was also used in a separate supply-chain attack poisoning dozens of Red Hat packages.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    franperez66q@protonmail.com
    • Website

    Related Posts

    Trump sued over “brazen” scheme to sell Truth Social API access for $100K a month

    August 13, 2026

    Twitch content has trained Amazon AI for years, but users can opt out now

    August 13, 2026

    South Korea Kospi bull market: SK Hynix, Samsung surge

    August 13, 2026

    Have physicists finally discovered glueballs? New evidence points to yes.

    August 13, 2026

    Cerebras (CBRS) Q2 earnings report 2026

    August 13, 2026

    The web’s newest weapon against AI scrapers is a font

    August 13, 2026
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Peterborough residents urged to avoid fireworks in heat spell

    August 13, 2026

    Maersk shares jump after shipping giant beats estimates, hikes outlook

    August 13, 2026

    Trump sued over “brazen” scheme to sell Truth Social API access for $100K a month

    August 13, 2026

    Clacton voters go to the polls in Westminster by-election

    August 13, 2026
    © 2026 All right reserved
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.