/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft has shut down 70+ of its own repositories on GitHub after hackers pushed malware that would steal credentials from users of AI coding agents

Microsoft took the highly unusual step of shutting down more than 70 of its own GitHub repositories after hackers pushed malware …

404 Media Joseph Cox

Context & Ripple Effects

The incident follows a broader pattern of GitHub being used to host or distribute malware, including a May supply-chain attack that infected thousands of repositories through automated commits. Microsoft had also previously faced a separate exposure involving an AI research repository containing sensitive data.

The affected repositories included Azure-related tools, making the response consequential beyond a single code project: Microsoft’s public GitHub presence is both a software-distribution channel and part of its developer-facing infrastructure.

First-order effects

  • Microsoft has removed more than 70 repositories from public availability, interrupting access to affected code and tools while it contains the malicious commits.
  • Users of AI coding agents who interacted with compromised repositories face credential-theft risk; Microsoft and affected users must treat repository provenance and exposed credentials as potentially compromised.

Second-order effects

  • Developers and organizations consuming Microsoft-hosted GitHub code will need to validate forks, dependencies, cached artifacts, and automated update paths rather than assuming official ownership is sufficient assurance.
  • The episode raises the operational cost of distributing developer tooling through public repositories, especially where automated commits and AI-agent credentials can turn a repository compromise into downstream account access.

Third-order effects

  • If attacks on trusted repositories continue, software suppliers will be pushed toward stronger controls around commit automation, release signing, credential scoping, and rapid revocation—not merely repository-level access controls.
  • AI coding agents create a more valuable target at the software supply-chain layer because their credentials can connect code ingestion to broader development environments; the lasting impact will depend on whether platforms and vendors make those credentials less reusable after compromise.

The trend: This is part of the shift from attacks on individual developers to attacks on trusted software-distribution channels and the credentials used by AI-assisted development tools.

Discussion

  • @malwrhunterteam @malwrhunterteam on x
    Totally legit “DocuSign” release in a GitHub (Microsoft owned service) repo: https://github[.]com/lonergigs-code/ DocuSign/releases/ -> DocusignSetup.exe - “Paula Foster” (Microsoft given cert) signed sample... -> bbytati25iy2.anondns[.]net -> 84.54.33[.]250 🤷‍♂️ [image]
  • @adnanthekhan Adnan Khan on x
    It appears miasma has made it back to @Microsoft. https://github.com/... https://github.com/...
  • Paul McCarty Paul McCarty on linkedin
    Looks like Microsoft has been compromised again!  All signs point to the Miasma worm (not confirmed), as evidenced by a probable reinfection of the durabletask repo/maintainer on GitHub. …
  • @josephcox Joseph Cox on bluesky
    New: Microsoft was compromised to deliver malware to users of AI coding agents like Claude and Gemini.  In response, Microsoft took the highly unusual step of shutting down dozens and dozens of its own GitHub repos.  The malware would steal login credentials from users  —  www.40…
  • @jasonkoebler Jason Koebler on bluesky
    Microsoft shut down a bunch of its own code repositories after hackers pushed malware that would steal credentials from Claude Code or Gemini.  Really wild:  —  www.404media.co/microsoft-ha...
  • r/GeminiAI r on reddit
    Microsoft Hacked to Deliver Malware to Claude and Gemini Users
  • r/AIDangers r on reddit
    Microsoft Hacked to Deliver Malware to Claude and Gemini Users