Microsoft’s Open-Source AI Tools Fall Victim to Supply Chain Attack, Leading to Theft of Numerous Developer Credentials
2026-06-09 / Read about 0 minute
Author:小编   

Microsoft has taken swift action to revoke access to no fewer than 70 open-source projects hosted on GitHub, following a supply chain attack perpetrated by hackers. The attackers sought to exploit AI coding applications as a means to pilfer user passwords and sensitive data. In response to the incident, Microsoft conducted a thorough investigation, during which it temporarily removed the affected repositories. Some of these projects have since been reinstated after undergoing a comprehensive review process. This marks the second security breach involving Microsoft’s open-source projects within a short span of time. Earlier, in mid-May, the open-source tool Durable Task was compromised, and the current attack is seen as a recurrence of such security lapses.
Against the backdrop of the increasingly seamless integration of large AI models with open-source ecosystems, open-source supply chains have emerged as a new frontier for cyber attacks and defenses. Establishing more robust code review procedures and security protection mechanisms has thus become a pressing issue that tech giants must urgently tackle in the era of AI.