Microsoft Packages Compromised with Credential Stealer for the Second Time

Recent incidents reveal that Microsoft’s open-source packages have been infiltrated with malicious credential-stealing code, raising concerns among developers.

3 min readTechnology

In a troubling development, numerous open-source packages from Microsoft have been found to contain sophisticated credential-stealing malware. This issue emerged late last week when 73 packages were identified as harmful by automated detection systems on GitHub, which promptly blocked them. Instead of alerting developers about the potential risks associated with these packages, GitHub, owned by Microsoft, cited a breach of its terms of service as the reason for the packages' removal and advised the owners to reach out for further assistance. The situation escalated when Microsoft acknowledged the possibility of compromise only on Monday, stating that they had temporarily taken down certain repositories while investigating the matter. Developers are now advised to treat their systems as potentially compromised if they have interacted with these packages, emphasizing the need for caution in their coding practices.

Technology