Microsoft hacked: distributing malware to Claude and Gemini users

Microsoft has shut down some of its own repositories on GitHub, including those related to Azure and artificial intelligence coding agents, as it investigates a data breach, according to a study by cybersecurity researchers.

Hackers planted malware that can harvest user credentials from AI coding tools like Claude Code or Gemini CLI, according to a team of researchers. The exact details of the breach are not known, but researchers say Microsoft has disabled more than 70 of its own repositories and is investigating a specific package that was compromised.

See more articles from iGuRu.gr when you search for news on Google.

Last week, cybersecurity website OpenSourceMalware.com , which acts as a clearinghouse for attack vectors so researchers can secure their own networks, wrote about the mass deactivation of Microsoft's GitHub repositories.

“GitHub disabled 73 Microsoft repositories across four organizations – the entire Azure Functions organization, the entire Durable Task family, and a number of sample AI applications – in a 105-second scan on June 5,” the site wrote on Friday.

It's very unusual for any company, let alone Microsoft, to disable so many of its own repositories... Of these, 49 are related to Azure, Microsoft's cloud computing arm, and a few are related to AI agents. The repositories that were shut down also include repositories related to durabletask, a Microsoft development tool.

Researchers from StepSecurity wrote on Friday that the GitHub shutdowns came after a malicious commit was pushed to the durabletask repository. This attack planted configuration files that would collect the credentials of people using the Claude Code, Gemini CLI, Cursor, or VS Code repositories.

Microsoft stated:

“Our priority is to protect our customers and the wider ecosystem. We have temporarily removed some repositories as we investigate potential malicious content. Some of these repositories have been restored after review, while others may remain offline while work continues. As part of our investigation, we have notified a small number of customers who may have downloaded content from the affected repositories. We will continue to investigate and if anything further is identified that requires action from the customer, we will contact them directly through our established support channels.”


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).