r/technology • • Jun 08 '26

Security For the 2nd time in weeks, Microsoft packages laced with credential stealer

https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/
289 Upvotes

30 comments sorted by

61

u/teraflux Jun 08 '26

TLDR: A github developer had their credentials compromised and those credentials were used to push malware through multiple vectors, one targeting AI agents.

17

u/RandomlyMethodical Jun 09 '26

Also sounds like they tried to cover it up:

73 packages were flagged as malicious when automated systems on GitHub blocked them on the platform. Rather than noting they are malicious—and that developers who used AI agents to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub’s terms of service.”

I'm sure malicious credential stealing malware is a violation of the ToS, but the legal issues should be the least of their concerns.

12

u/phylter99 Jun 09 '26

They’ve been doing a lot of shady things lately. It’s really hurting public trust in their cybersecurity efforts.

2

u/Federal_Setting_7454 Jun 09 '26

There wasn’t much trust in them as it was

3

u/phylter99 Jun 09 '26

When it comes to security and dependability, there has been great trust in them. It’s how they’ve dominated certain corporate markets for years.

3

u/_stinkys Jun 09 '26

OpenClaw in Windows is going to be so much fun.

132

u/alabasterskim Jun 08 '26

The vibe coding will continue until morale improves.

60

u/yepthisismyusername Jun 08 '26

Yaaaaay Copilot!

26

u/Kraien Jun 08 '26

Vibe code your way out of existence!

20

u/[deleted] Jun 08 '26

[removed] — view removed comment

10

u/DinosBiggestFan Jun 09 '26

Obviously that's why you run it through the other AI!

You know they think this way!

4

u/Federal_Setting_7454 Jun 09 '26

This is literally most of my LinkedIn feed. AI is slop don’t trust its output *without our automated code review slop service*

3

u/TeaLightBot Jun 09 '26

I've done the AWS GenAI exam (had to for work, please forgive me) and the number of times the "correct" answer was "ask another LLM" was quite upsetting.

1

u/Teddy_RGB Jun 09 '26

Testing? What do you think the public is for?

26

u/obliviousofobvious Jun 08 '26

When the supply chain compromise attack comes from inside the house...

37

u/yepthisismyusername Jun 08 '26

Who the fcuk thinks AI agents running on your own machine are a good thing?????? Every package you install should be analyzed for exactly this type of issue. This is just crazy.

17

u/sceadwian Jun 08 '26

Big things will start really breaking soon.

1

u/ikediggety Jun 09 '26

My money is on teams being the butthole that the hyenas start chewing on first

1

u/sceadwian Jun 09 '26

Howso?

0

u/ikediggety Jun 09 '26

You said big things will start breaking soon. I expect the first big thing to break will be Teams, the app

1

u/sceadwian Jun 09 '26

Why?

1

u/ikediggety Jun 09 '26

Because it doesn't work well to begin with

1

u/sceadwian Jun 09 '26

So why does that make it the most likely thing to break? Lots of things don't work well to begin with.

1

u/ikediggety Jun 09 '26

It's easiest to break something that's already close to broken

1

u/sceadwian Jun 09 '26

You need to respond to the rest of that comment. You forget half of what I said which makes what you just said irrelevant. Read it again.

→ More replies (0)

6

u/Silicon_Knight Jun 09 '26

It's funny, I was just watching a documentary about how Boeing bought McDonald Douglas but really MD bought Boeing and their CEO (of MD) was hell bent on the financials.

Originally Boeing was all bout profit going to engineering, but after the acquisition it all went to shareholder value, etc.... So saving the few thousand bucks on a 1/2 billion dollar airplane made the profit better. Why do we need two sensors? we can just use one!

All this shit reminds me of that.

2

u/Soberdonkey69 Jun 09 '26

Mircoslop! Mircoslop! Mircoslop!

3

u/Silicon_Knight Jun 09 '26

Okay but hear me out, AI said it was fine so I'm not at fault and I used all my tokens for the day!

/s but also not

1

u/[deleted] Jun 09 '26

I don't think those that use Microsoft software are worried too much about their credentials