Key facts
- Microsoft has removed dozens of its open source projects from GitHub following a security breach.
- Hackers injected malware into the code, designed to steal passwords and sensitive credentials from AI developers.
Microsoft has temporarily removed dozens of its open source projects on GitHub due to a security breach. Hackers injected malware into code used by AI developers, potentially stealing passwords and sensitive credentials.

This incident highlights the significant risks associated with supply chain attacks in the open source ecosystem, even affecting major technology providers like Microsoft, and underscores the potential for widespread compromise of developer credentials and sensitive data.
Microsoft has temporarily removed dozens of its open source projects hosted on GitHub as it investigates a security breach where hackers injected password-stealing malware into the code. The compromised tools are used by developers, particularly those working with AI development applications like Claude Code, Gemini's command line interface, and VS Code.
Security firms Cloudsmith and OpenSourceMalware were among the first to report the incident. The malware reportedly allowed attackers to steal users' passwords and other sensitive credentials when they accessed the compromised tools. It remains unclear how many individuals downloaded the affected software.
A Microsoft spokesperson, Ben Hope, confirmed that repositories were temporarily removed due to potential malicious content, with some being restored after review and others remaining offline. The company has notified a small number of customers who may have accessed the compromised content.
At least 70 Microsoft projects were disabled on GitHub, with a message indicating a violation of the platform's terms of service. This incident is the latest in a series of 'supply chain' attacks targeting widely used open source projects to distribute malware. It is particularly notable given Microsoft's resources for cybersecurity, making it a rare target for such breaches.
Pick the topics you care about. Get only what matters, on your cadence.