For the second time in weeks, Microsoft packages have been found laced with credential-stealing code designed to activat...

For the second time in weeks, Microsoft packages have been found laced with credential-stealing code designed to activate when developers open them in AI coding agents. 73 packages were blocked on GitHub, executing a payload that steals credentials from AWS, Azure, GCP, Kubernetes, password managers and over 90 developer tools. https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/ #AIagent #AI #GenAI #AISecurity

Read Original

Related