Microsoft has disabled dozens of its open-source GitHub repositories after hackers breached the projects to inject password-stealing malware targeting AI developers.
The compromised projects are heavily tied to Microsoft’s Azure cloud ecosystem and vital utilities utilised by engineers to build artificial intelligence applications. These include popular tools such as Claude Code, Gemini’s command-line interface, and VS Code.
Malware Targets Claude and Gemini Users
According to findings from security firm Cloudsmith and the community-led platform OpenSourceMalware, who initially flagged the threat, the malicious payload harvests user passwords and sensitive credentials. This security compromise occurs the moment developers open the infected tools within their AI-assisted coding applications.
Currently, the exact volume of users who have downloaded these compromised tools remains undetermined.
Microsoft Confirms GitHub Repositories Disabled
The tech giant has officially confirmed the removal of these repositories, following an initial report by 404 Media.
Microsoft spokesperson Ben Hope stated that the corporation has “temporarily removed some repositories as we investigated potential malicious content.” Hope further clarified that “some of these repos have been restored after review, while others may remain offline while work continues.”
As part of the ongoing mitigation efforts, the company has reached out to a select group of users. “As part of our investigation, we notified a small number of customers who may have pulled down content from the affected repositories. We will continue to investigate, and if anything further is identified that requires customer action, we will reach out directly through our established support channels,” Hope added. Microsoft declined to share the precise number of impacted clients when prompted.
At least 70 Microsoft-owned projects on GitHub—the code-hosting platform owned by Microsoft itself—currently display a suspension notice. Visitors attempting to access these pages are met with a message stating: “Access to this repository has been disabled by GitHub Staff due to a violation of GitHub’s terms of service.”

The Rising Threat of Supply Chain Attacks
This incident represents the latest in a worrying trend where threat actors compromise widely adopted open-source code to distribute malware on a massive scale. Known as “supply chain attacks”, these operations strategically target foundational code embedded in numerous downstream software products. By targeting developers, hackers frequently gain indirect access to highly secure cloud infrastructures and vast repositories of sensitive customer data.
While independent open-source maintainers are frequently targeted by malicious actors—often via sophisticated, long-term social engineering campaigns designed to win developer trust—it is highly unusual for a tech titan of Microsoft’s scale and defensive capabilities to suffer such a breach.
A Repeat Security Failure?
Concerningly, this marks Microsoft’s second major open-source security failure in just a matter of weeks, as reported by Ars Technica. In mid-May, cybersecurity researchers discovered that Microsoft’s “Durable Task” project—a framework designed to help developers orchestrate workflow applications—had been compromised.
According to OpenSourceMalware, this latest incident appears to be a “re-compromise” of the Durable Task ecosystem. This strongly suggests that Microsoft either failed to completely purge the attackers during the initial remediation process, or has fallen victim to an entirely separate, concurrent security breach.
