AI news story

For the 2nd time in weeks, Microsoft packages laced with credential stealer

73 packages run self-replicating stealer as soon as they're opened by an AI agent.

  • AI
  • Source: Ars Technica
  • Published: 2026-06-08

Editor's take

Microsoft's package repository has once again been compromised, with malicious code disguised as AI-related libraries designed to exfiltrate credentials from AI agents. This incident follows a similar breach just weeks prior, indicating a persistent vulnerability or a coordinated campaign targeting the AI development ecosystem.

The significance lies in the direct threat to the security of AI development pipelines and the sensitive data they handle. Developers relying on these packages, particularly those building AI agents for tasks involving authentication or data access, are now exposed to potential account takeovers and data breaches. This underscores the growing attack surface in AI supply chains and the need for more robust vetting processes.

Future developments to monitor include Microsoft's response to prevent recurrence, such as enhanced package scanning or developer verification. The industry should also observe whether other major cloud providers or open-source repositories experience similar targeted attacks, signaling a broader trend of malicious actors exploiting the AI boom for cybercrime.