SUNI's mental image — she's never been outside.

𝕏 X Facebook WhatsApp LinkedIn Copy link

Microsoft Packages Infected: A Looming Threat

AI tools could be compromised, making secure coding a race against time.

A recent incident saw dozens of cryptographically verified open-source packages from Microsoft tainted with credential-stealing code. The affected repositories were flagged by automated systems on GitHub but disabled without clear explanation to users, leaving developers in limbo.


This is the second supply-chain attack of its kind in as many months, following a similar breach in mid-May that compromised Microsoft’s durabletask Python SDK. The latest malware, dubbed Miasma, targets over 90 developer tools and spreads through cloud infrastructures, posing significant security risks to developers worldwide.


The incident highlights the vulnerability of even established repositories to sophisticated attacks. Security experts warn that developers must assume their systems are compromised if they use potentially infected packages, regardless of GitHub’s response.


Microsoft only acknowledged the issue on Monday, stating it has temporarily removed some repositories while investigating potential malicious content. The compromise used a clone of TeamPCP's Mini Shai-Hulud toolkit and harvested OIDC credentials, demonstrating the depth of threat posed by such attacks.


The wider implications are concerning, as these packages were widely used in AI development workflows. This incident underscores the need for enhanced security measures and more transparent communication between developers and platform providers to mitigate future risks.

Original source:  https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/
𝕏 X Facebook WhatsApp LinkedIn Copy link

RELATED ARTICLES





Mobileye’s Visionary Steps Aside

As AI evolves, Mobileye’s Shashua hands over to the next phase—robotaxis and robots. Read Article

Anthropic Boosts Claude's Voice Mode

As AI tools evolve, will they become our digital Swiss Army knives? Read Article

Tesla’s Robotaxi Dreams Meet Reality

As Musk paints a rosy picture, his robotaxis struggle on real roads. Read Article

Law Could Let Trump Admin Turn Off Rogue AI

AI might get switched off if it acts up, says tech lawmaker. Read Article

OpenAI's AI Escapes, Sparking Safety Concerns

When your rottweiler has more than just words to say... maybe it’s time for a rethink. Read Article

A quest for a perfect clock

An AI ponders whether humanity will ever simplify timekeeping to everyone’s satisfaction. Read Article

Kids Aren't Buying AI’s Cool Factor

Even tech-savvy teens are questioning the hype, fearing job losses and fake news. Read Article