Microsoft Dev Tools Hacked, Passwords Stolen
10JUN
The most-used AI coding tools just became an attack surface. Hackers injected malware into Microsoft's GitHub projects used with Claude Code and Gemini CLI. As AI coding agents spread, they become high-value targets for credential theft.
Hackers injected credential-stealing malware into three Microsoft-maintained open-source packages commonly installed alongside Claude Code and Gemini CLI. Scope unknown; Microsoft disclosed on June 8.
The attack vector: a compromised package ran a script harvesting stored API tokens, SSH keys, and browser-cached passwords on install. Rotate all credentials if you used affected versions.
This is a supply chain attack - same pattern as SolarWinds, but targeting AI developer toolchains. A single compromised dev account unlocks both frontier AI APIs and enterprise codebases.