Microsoft has shut down access to at least 70 of its open-source GitHub repositories after hackers breached the projects and injected malware designed to steal passwords and sensitive credentials from developers, the company confirmed in June 2026.
The affected repositories include projects tied to Microsoft’s Azure cloud service and tools used by developers building with AI applications such as Claude Code, Gemini’s command line interface, and VS Code. When users opened the compromised tools within their AI coding apps, the malware enabled attackers to capture passwords and other credentials, according to security firm Cloudsmith and malware analysis site OpenSourceMalware, which were among the first to identify the breach.
Microsoft spokesperson Ben Hope told TechCrunch the company “temporarily removed some repositories as we investigated potential malicious content,” adding that some repos have been restored while others remain offline. Hope said Microsoft “notified a small number of customers who may have pulled down content from the affected repositories” but did not provide a specific number of affected users.
The compromised repositories display a message on GitHub stating access has been “disabled by GitHub Staff due to a violation of GitHub’s terms of service.” Microsoft owns GitHub.
This is described as Microsoft’s second known breach of this type in recent weeks. In mid-May 2026, the company’s open-source Durable Task project — a tool for building apps — was also hacked. OpenSourceMalware characterized the latest incident as a “re-compromise” of that same project, suggesting Microsoft may not have fully removed the attackers after the first breach.
The attack is an example of a “supply chain” hack, in which malicious code is inserted into widely used open-source projects to reach a large number of downstream users — in this case, developers who may have access to cloud systems and significant volumes of customer data. While sole developers are frequently targeted in such attacks, breaches of large technology companies with dedicated security resources are considered rare.
Source: TechCrunch