Key facts
- Microsoft has removed dozens of its open source projects from GitHub following a security breach.
- Hackers injected malware into the code, designed to steal passwords and sensitive credentials from AI developers.
- Affected projects include tools related to Azure, Claude Code, Gemini's command line interface, and VS Code.
- At least 70 projects were disabled on GitHub for violating terms of service.
- Microsoft has notified a small number of potentially affected customers.
Microsoft has temporarily removed dozens of its open source projects hosted on GitHub as it investigates a security breach where hackers injected password-stealing malware into the code. The compromised tools are used by developers, particularly those working with AI development applications like Claude Code, Gemini's command line interface, and VS Code.
