← Back to feed
TechJun 9100% confidenceConfidence 100% — the share of independent, credible sources corroborating the core facts.

Microsoft Open Source Packages Compromised with Credential-Stealing Code for Second Time in Weeks

Center 100%
4 sources

GitHub disabled 73 Microsoft-owned repositories on June 5 after automated systems detected the Miasma credential-stealing worm had been injected into the code. The attack is the second supply-chain compromise of Microsoft's open source infrastructure in as many months, with security researchers suggesting unrotated credentials from a May breach enabled the repeat intrusion. The incident disrupted developer CI/CD pipelines worldwide and exposed cloud credentials across AWS, Azure, GCP, and Kubernetes environments.

On June 5, GitHub's automated detection systems disabled 73 Microsoft repositories across four organizations — Azure, Azure-Samples, microsoft, and MicrosoftDocs — within 105 seconds of detecting signs of the Miasma worm, a credential-stealing malware descended from the Mini Shai-Hulud toolkit open-sourced by cybercrime group TeamPCP. The attack began when a compromised contributor account pushed a malicious commit to Azure/durabletask, dropping configuration files that triggered remote code execution when developers opened the repo in AI coding tools such as Claude Code, Gemini CLI, VS Code, or Cursor. The malware harvested credentials from AWS, Azure, GCP, Kubernetes, password managers, and over 90 developer tool configurations, then spread laterally through cloud infrastructure. Security researchers at StepSecurity noted the attack appears to be a re-compromise of the same durabletask project hit in May 2025, suggesting Microsoft failed to fully rotate the GitHub Actions secrets stolen in that earlier breach. The Azure org bore the heaviest impact, losing 49 repositories, and every workflow referencing Azure/functions-action@v1 stopped resolving, breaking CI/CD pipelines for an unknown number of developers. Microsoft initially described the takedowns only as a 'terms of service violation' before later acknowledging it was investigating 'potential malicious content'; by June 10, the company stated all repos had been restored and that a small number of affected customers had been notified.

What's missing

The total number of developers or downstream users who actually executed the malicious code remains undisclosed; Microsoft declined to provide a specific figure. It is also unclear whether Microsoft has confirmed full credential rotation following this second incident.

How coverage differed

Ars Technica was notably more critical of Microsoft's response, emphasizing the company's delayed and opaque communication — specifically calling out the 'terms of service violation' framing as misleading — while TechCrunch and The Register reported Microsoft's official statements more neutrally and gave greater weight to the company's eventual remediation steps.

What different sources said

  • For the 2nd time in weeks, Microsoft packages laced with credential stealer

  • Microsoft’s open source tools were hacked to steal passwords of AI developers

  • TechRadarCenter

    Microsoft disables over 70 GitHub repos after hackers compromised them with dangerous malware

  • GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections

Related

TechConfidence 69% — the share of independent, credible sources corroborating the core facts.

Samsung Galaxy S25 and S25 FE See Significant Price Cuts

Samsung's Galaxy S25 and Galaxy S25 FE smartphones are currently available at notably reduced prices, with the S25 FE dropping $201 (33%) to $449 on Woot for a limited time. The price reductions come amid a competitive smartphone market and ahead of anticipated future Samsung releases. The discounts make previously premium-priced devices more accessible to budget-conscious consumers.

2 sourcesJun 16
TechConfidence 100% — the share of independent, credible sources corroborating the core facts.

Anthropic Disables Fable 5 and Mythos 5 AI Models Globally After US Government Export Control Order

Anthropic has suspended all public access to its two most advanced AI models, Fable 5 and Mythos 5, after the US Commerce Department issued an export control directive ordering the company to block foreign nationals from accessing them on national security grounds. The order came just three days after Fable 5's public launch and reportedly stems from government concerns about a potential jailbreak that could enable the models to assist with cyberattacks, though Anthropic says it received only verbal evidence of a narrow, non-universal vulnerability. The shutdown affects all customers globally — including enterprise users and Anthropic employees — and marks a significant escalation of US efforts to restrict foreign access to advanced AI models themselves, rather than just the chips that power them.

4 sourcesJun 16
TechConfidence 89% — the share of independent, credible sources corroborating the core facts.

Xbox Free Play Days Offers Three Games Free to Play June 11–14

Microsoft's Xbox Free Play Days program is offering Hell Let Loose, State of Decay 2: Juggernaut Edition, and Blasphemous 2 at no cost from June 11 to June 14. Hell Let Loose requires an Xbox Game Pass Ultimate, Premium, or Essential membership, while State of Decay 2 and Blasphemous 2 (via a five-hour timed trial) are accessible to all Xbox console owners. Players who wish to keep any of the games can purchase them at a limited-time discount and retain any achievements earned during the free period.

2 sourcesJun 13