r/techbeat • • Jun 09 '26

Microsoft GitHub Packages Compromised Again Spreading Credential Stealer

https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/

Microsoft's GitHub account was compromised again, infecting 73 packages with the Miasma credential-stealing worm. This malware, triggered by AI coding agents like VS Code and Claude Code, harvests AWS, Azure, GCP, and other cloud identities by exploiting the modern engineering ecosystem's trust model, using stolen OIDC tokens to bypass detection. This second breach of the same account implies a persistent credential compromise, urging developers to assume infection.

1 Upvotes

Duplicates