- Hackers injected malware that steals credentials into many open-source software packages that belong to Microsoft, which it was hosting on GitHub.
- GitHub stopped a total of these 73 repositories in all the organizations that have links to Microsoft after researchers found the presence of the malicious code.
- Microsoft has also removed the repositories that hackers hijacked and started to investigate the issue.
An attack, which experts in cybersecurity call a “supply-chain attack,” has exposed many developers to credential theft through their download of malicious software. Hackers compromised many open-source packages which Microsoft was hosting on GitHub.
Security researchers found out that bad actors inserted malicious code into these packages, which developers get from Microsoft repositories. The code allows the threat actors to grab their passwords, API keys, authentication tokens, plus many other sensitive credentials from developer environments.
As soon as GitHub got wind of this incident, it disabled 73 repositories in all the organizations that have links to Microsoft in a very swift action.
Microsoft later made announcements that there was indeed credential-stealing malware in these repositories. It also removed the ones with malicious codes while continuing its investigation of the attack.
The attack is a testament to the risk facing developers who base their work on trusted open-source software components plus AI-assisted coding tools.
Hackers Used Microsoft Repositories Many Developers Trust to Deliver Malware
The attack was actually troubling for all because the packages that bad actors hijacked appeared legitimate. Researchers found that hackers added the malicious code inside Microsoft packages that were cryptographically verified.
The trust in the company made the developers believe they were trustworthy, leading them to download & use them.
According to security researchers, cybercriminals designed the malware, going by “Miasma,” to maliciously gather credentials people store within developer environments, and these include their passwords, API keys and tokens they use for authentication.
The packages that contained these malware have links to repositories across Microsoft, Azure-Samples, plus Azure, & other MicrosoftDocs organizations on GitHub. Once the researchers found this malware, GitHub disabled 73 repositories in a few minutes to make sure the threat didn’t spread.
According to security news reports, the researchers sent warning to developers who use coding platforms assisted by AI such as Visual Studio Code, Gemini CLI plus Claude Code, that they might have already gotten the malware if they have used the tools with the malware.
Reports showed that security experts have attributed this incident to a threat group popularly known as TeamPCP. The group in previous times targeted developer services & software ecosystems which many people trusted to collect high-value credentials & infrastructure.
Microsoft Responds as Investigation Continues
This discovery resulted in immediate responses and subsequent actions from both GitHub & Microsoft. First GitHub stopped all access to the repositories, citing malware on the premise that they violated its terms of service.
Microsoft later told the public that its experts found malware that steals credentials within many repositories belonging to the company and that it has removed the projects temporarily while continuing to investigate the incident.
After some time, the company restored some of the repositories after reviewing them, while others are still off the grid as its security teams continue their analysis.
Microsoft also stated that it sent a direct message to some of the customers who may have gotten some contents from the repositories with malware. Even though Microsoft has not revealed the number of developers that have become victims of this attack, it promised that remediation efforts are ongoing.
Meanwhile, Google has taken a different approach to Microsoft’s security issues. The company publicly disclosed unpatched, actively exploited bugs used by Russian hackers, putting pressure on Microsoft to respond.
What the company is focusing on right now, according to the response, is removing malicious content, checking to find the projects with malware & finding out the customers who may have downloaded malware from the packages.
What Potential Victims Should Do
To be on the safe side, security experts recommend that developers who might have downloaded or even used packages from the Microsoft repositories should check if there are signs of unauthorized activity in their environment.
This is because threat actors designed the Miasma malware to collect passwords, API keys, plus authentication tokens, & other credentials.
So those users who don’t know yet if the hackers have their main credentials should now make it a priority to rotate any credentials that may have remained on those systems where they used the compromised packages.
On the other hand, organizations should also recheck access logs now for cloud services, source-code repositories, plus developer platforms to find login activities that are unusual.
Since hackers could use the credentials they stole to gain deeper access to development infrastructure, looking out for unauthorized repository changes or cloud activity that is suspicious is really important.
Microsoft has hinted that it is reaching out to customers its team identified during the investigation. So developers who have used these packages should watch out for official communications from Microsoft & GitHub for more guidance on what to do.
Share this article
About the Author
Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.
More from Rebecca JamesRelated Posts
Google and FBI Disrupt NetNut Residential Proxy Network Used by 2M+ Devices
Google worked with the FBI and Lumen to disrupt the NetNut residential proxy network, also known as ...
Opera Launches Paste Protect to Block ClickFix Clipboard Attacks
Opera’s Paste Protect blocks harmful commands from reaching the clipboard, preventing ClickFix...
Reddit Introduces Mandatory Age Verification for EU Teens Accessing NSFW Content
Reddit will require European Union users under 18 to verify their age before viewing mature or NSFW ...
Popular ‘Adblock for YouTube’ Chrome Extension Found With Remote Code Execution Risk
The popular “Adblock for YouTube” Chrome extension now carries an architectural weakness...
Texas Hunting and Fishing License Data Breach Affects 3 Million Customers
Approximately 3 million Texas hunting and fishing license customers were affected by a data breach i...
FBI Warns of ‘Kali365’ Subscription Service Targeting Microsoft 365 Accounts
The FBI’s sounding the alarm on Kali365, a site where criminals can pick up ready-to-use tools for s...