06/09/2026
Cybercriminals compromised 73 trusted open-source packages linked to Microsoft, embedding credential-stealing malware that activates when the packages are opened by AI coding assistants.
The attack targeted developers and used cryptographically verified packages, making the malicious code appear legitimate and more difficult to detect. Learn more and stay cyber aware!
73 packages run self-replicating stealer as soon as they're opened by an AI agent.