For the 2nd time in weeks, Microsoft packages laced with credential stealer

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

73 cryptographically verified Microsoft open source packages were compromised in a supply-chain attack that injected credential-stealing malware (Miasma) triggered when developers opened them in AI coding agents. This is the second such attack in weeks — the first targeted Microsoft's durabletask Python SDK on PyPI in May. The malware steals credentials from AWS, Azure, GCP, Kubernetes, password managers, and 90+ developer tool configs, then spreads laterally through cloud infrastructure. The attacker (TeamPCP) exploited stolen Microsoft publishing credentials to bypass build pipelines and harvested OIDC tokens used in SLSA provenance attestation. GitHub initially obscured the incident by citing only a 'terms of service violation' rather than disclosing the malicious nature of the packages.

2m read timeFrom arstechnica.com
Post cover image
Table of contents
Ars VideoWhat Happens to the Developers When AI Can Code? | Ars Frontiers
475 Impressions