
Dozens of cryptographically verified Microsoft open source packages were compromised to add credential-stealing code triggered when developers opened them in AI coding agents. GitHub disabled 73 flagged packages for violating terms of service. The incident is the second supply-chain attack in as many months to breach an official Microsoft repository account.
Tap to vote and see what everyone thinks.
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
Summary by ByteBrief