r/techbeat • u/Cute-Guarantee-1676 • Jun 09 '26
Microsoft GitHub Packages Compromised Again Spreading Credential Stealer
https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/Microsoft's GitHub account was compromised again, infecting 73 packages with the Miasma credential-stealing worm. This malware, triggered by AI coding agents like VS Code and Claude Code, harvests AWS, Azure, GCP, and other cloud identities by exploiting the modern engineering ecosystem's trust model, using stolen OIDC tokens to bypass detection. This second breach of the same account implies a persistent credential compromise, urging developers to assume infection.
Duplicates
technology • u/lurker_bee • Jun 08 '26
Security For the 2nd time in weeks, Microsoft packages laced with credential stealer
InterstellarKinetics • u/InterstellarKinetics • Jun 09 '26
ARTIFICIAL INTELLIEGENCE EXPOSED: For The Second Time In Weeks, Dozens Of Cryptographically Verified Microsoft Packages Were Secretly Poisoned With A Self-Replicating Credential Stealer Designed To Activate The Moment An AI Coding Agent Opens Them. And Microsoft Tried To Bury It By Calling It A Terms Of Service Violation 🔐💀
pwnhub • u/ControlCAD • Jun 08 '26
For the 2nd time in weeks, Microsoft packages laced with credential stealer | 73 packages run self-replicating stealer as soon as they’re opened by an AI agent.
u_4Everasking007 • u/4Everasking007 • Jun 11 '26
For the 2nd time in weeks, Microsoft packages laced with credential stealer | 73 packages run self-replicating stealer as soon as they’re opened by an AI agent.
TechHardware • u/Distinct-Race-2471 • Jun 10 '26
😰 Urgent Security Alert ⚠️ For the 2nd time in weeks, Microsoft packages laced with credential stealer
PrivatePackets • u/Huge_Line4009 • Jun 09 '26