Microsoft has cut off access to dozens of open source projects hosted on GitHub as it investigates how hackers apparently infiltrated the projects and injected password-stealing malware into the code.
Many of the affected projects are related to Microsoft's cloud service Azure and other tools that developers use to code in AI development apps, such as Claude Code, Gemini's command line interface, and VS Code.
According to security firm Cloudsmith and community-driven malware analysis site OpenSourceMalware, which first reported the hack, the malware could steal users' passwords and other sensitive credentials when hackers opened compromised tools in AI coding apps.
It is currently unknown how many people have downloaded the affected tools.
As first reported by 404 Media, Microsoft has confirmed that it has removed the repository.
Microsoft spokesperson Ben Hope told TechCrunch that the company has “temporarily removed some repositories as we investigate potentially malicious content.”
“While some of these repositories have been restored after review, others may remain offline while work continues.”
“As part of our investigation, we have notified a small number of customers who may have pulled down content from the affected repositories. We continue to investigate and if we identify further customer action that requires action, we will contact them directly through our established support channels,” Hope added.
In response to questions from TechCrunch, Microsoft did not immediately reveal the specific number of customers affected.
At least 70 projects belonging to Microsoft have been “deactivated,” according to a message that loads when you try to access the project's page on GitHub, a code hosting site owned by Microsoft. “Access to this repository has been disabled by GitHub staff for violating GitHub's Terms of Service.”
Image credit: TechCrunch /
This is the latest example in recent months of hackers breaking into widely popular open source projects with the goal of planting malware on large numbers of users who have the code installed on their computers. These hacks are known as “supply chain” attacks because they target code that is frequently used by many software products and specific types of users. Users may have access to cloud systems and large amounts of customer data, which could be advantageous for hacking.
While solo developers of open source projects are often targeted by hackers, sometimes as part of long-term efforts to gain developer trust, it is rare for large technology companies like Microsoft, which have the resources to defend against these types of attacks, to be compromised.
According to Ars Technica, this is the second known breach in which Microsoft has allowed hackers to compromise its open source projects in the past few weeks. In mid-May, security researchers announced that Microsoft's open source project Durable Task, a tool that helps developers build apps, had been hacked. OpenSourceMalware says Microsoft's latest incident is a “re-compromise” of the Durable Task project, suggesting that Microsoft may not have been able to eradicate the hackers on the first attempt or with a completely new and clear breach.
Updated with comment from Microsoft.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

