NEWS 73 repositories in 105 seconds. Hackers have hacked twice Microsoft projects. What is the extent of the damage that the company is silent about?

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,687
In Microsoft’s projects, they found malicious code aimed at developers working with AI.

1781013655844.png
Even large technology companies do not always have time to notice the danger where developers are accustomed to trust the code almost automatically. Microsoft temporarily closed access to dozens of its open projects on GitHub after malicious code was found in terms of repositories that stole passwords and other accounts.

Projects associated with the Microsoft Azure, Durable Task and the tools that developers use when they write code with AI assistants hit were hit. Among these media were the Claude Code, the command interface Gemini, Cursor and Visual Studio Code. According to CloudsmithCloudsmith, OpenSourceMalware and StepSecurity, attackers added configuration files to the projects that could steal secrets when the user opened an infected repository in a development environment.

Microsoft confirmed that it temporarily removed part of the repositories for the duration of the audit. The company’s spokesman Ben Hope сообщилsaid that some projects have already been restored after analysis, while others remain unavailable while the audit continues. The company also notified a small number of customers who could download the contents of the affected repositories. How many users or organizations were affected, Microsoft did not disclose.

According to OpenSourceMalware, on June 5, GitHub turned off 73 Microsoft repositories in four organizations in 105 seconds. Among them were the entire organization Azure Functions, the Durable Task family and a number of examples of applications with AI. On the pages of the disabled projects, a message appeared that access to the repository is closed by GitHub employees due to violation of the terms of the service.

The incident looks especially alarming because of the connection with the previous burglary. In May, the attackers have already attacked the Durable Task project and published three malicious versions of the tool. OpenSourceMalware called the new case a second compromise of the Durable Task. Such a scenario may mean that Microsoft did not completely supplant the attackers after the first attack or faced a separate new hack.

The malware change in the Durable Task was designed for users who open the repository through development tools with AI. In this case, the program could access passwords, tokens and other secrets, which developers often need to work with cloud systems, code storage and internal infrastructure.

The attack refers to the compromise of the supply chain. In such cases, attackers do not hit the final target directly, but on the code or libraries that other developers and companies trust. This approach is especially dangerous when an infected project is used by people with access to cloud services, work environments and customer data.

When repositories were disabled, it could disrupt the operation of automatic processes on GitHub, if the builds or worklines depended on closed Microsoft projects. In discussions at forums, users complained that the company publicly almost did not explain the scale of the problem. While Microsoft continues to check, the affected developers will have to revise the downloaded copies of projects, check the accounts and replace the secrets that could get into the wrong hands.
 
6,444Threads
87,319Messages
6,104Members
VoxiotLatest member
Top Bottom