By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
The Tech DiffThe Tech DiffThe Tech Diff
  • Home
  • Shop
  • Computers
  • Phones
  • Technology
  • Wearables
Reading: Microsoft Packages Again Found Containing Dangerous Credential Stealer
Share
Font ResizerAa
The Tech DiffThe Tech Diff
Font ResizerAa
  • Computers
  • Phones
  • Technology
  • Wearables
Search
  • Home
  • Shop
  • Computers
  • Phones
  • Technology
  • Wearables
Follow US
  • Shop
  • About
  • Contact
  • Terms & Conditions
  • Privacy Policy
© Copyright 2022. All Rights Reserved By The Tech Diff.
The Tech Diff > Blog > Technology > Microsoft Packages Again Found Containing Dangerous Credential Stealer
Technology

Microsoft Packages Again Found Containing Dangerous Credential Stealer

Admin
Last updated: June 14, 2026 3:36 pm
Admin
Share
Microsoft Packages Again Found Containing Dangerous Credential Stealer
SHARE

Contents
Malicious Packages IdentifiedAssuming CompromiseHow the Attack Was Executed

The cybersecurity landscape faced another significant setback last week when dozens of cryptographically verified open source packages from Microsoft were compromised. Malicious code designed to steal credentials was detected, triggered specifically when developers interacted with these packages using AI coding agents.

-28% Unlock Connectivity: Acer USB C Hub 7-in-1 Adapter & Charger!
Computer & Accessories

Unlock Connectivity: Acer USB C Hub 7-in-1 Adapter & Charger!

$24.99 Original price was: $24.99.$17.99Current price is: $17.99.
Buy Now
-14% Ergonomic Adjustable CPU Stand: Elevate Your Gaming & Office!
Computer & Accessories

Ergonomic Adjustable CPU Stand: Elevate Your Gaming & Office!

$69.99 Original price was: $69.99.$59.99Current price is: $59.99.
Buy Now
-25% Experience Sennheiser RS 120-W: Crystal-Clear Wireless Listening!
Headphones

Experience Sennheiser RS 120-W: Crystal-Clear Wireless Listening!

$159.95 Original price was: $159.95.$119.95Current price is: $119.95.
Buy Now
-20% Boost Your Workspace: NiHome Iridescent Acrylic Monitor Stand
Computer & Accessories

Boost Your Workspace: NiHome Iridescent Acrylic Monitor Stand

$25.99 Original price was: $25.99.$20.79Current price is: $20.79.
Buy Now

Malicious Packages Identified

Researchers have flagged 73 packages as having malicious intent after they were automatically blocked by GitHub’s security systems. In a somewhat concerning response, GitHub, owned by Microsoft, labeled the incident as a “violation of GitHub’s terms of service,” advising the package owners to reach out for further guidance rather than openly acknowledging the malicious nature of the compromised software.

Assuming Compromise

Only on Monday did Microsoft acknowledge the potential infection of the packages. An email communication stated: “We have temporarily removed some repositories as we investigate potential malicious content.” Developers are encouraged to assume that their systems may be compromised if they interacted with these packages.

This incident marks the second supply-chain attack targeting Microsoft’s repositories within the last few months. Notably, in May, StepSecurity highlighted a compromise involving Microsoft’s durabletask Python SDK on PyPI, a framework crucial for orchestrating fault-tolerant workflows, which garners around 400,000 downloads monthly.

How the Attack Was Executed

The malicious packages executed a 28 KB payload that was adept at stealing credentials from various services, including AWS, Azure, Google Cloud Platform, Kubernetes, password managers, and more than 90 developer tool configurations. The attack was executed by a threat actor identified as TeamPCP, who exploited Microsoft’s own credentials to publish the compromised durabletask package. This method enables attackers to bypass standard security protocols effectively.

The malware responsible for these attacks is known as Miasma. This tool is essentially a replica of TeamPCP’s Mini Shai-Hulud toolkit, which had been recently open-sourced. According to security experts at Cloudsmith, the malware efficiently harvests OpenID Connect (OIDC) token credentials, which are vital for supply-chain integrity assurance, i.e., ensuring that software artifacts are authentic and have not been tampered with.

Similar to the earlier incident with the durabletask SDK, the recent compromise leveraged the inherent functionality of Microsoft’s repositories to obtain legitimate OIDC tokens. This tactic was also previously employed in a broader scale supply-chain attack that tainted numerous packages within the Red Hat ecosystem.

As the frequency of these attacks rises, meticulous vigilance is essential for developers working in the ecosystem. Regularly updating security measures and maintaining awareness of potential vulnerabilities can help mitigate the risks posed by such evolving threats.

For more detailed information on this alarming incident, please follow this link.

Image Credit: arstechnica.com

You Might Also Like

“Amazon Security Research Sparks White House Ban on Anthropic Fable”

“AI Leaders Unite on Critical Security Challenge”

FBI Creates Replica Town to Simulate Cyberattack Scenarios

“PeopleSoft 0-Day Breach Hits Hundreds, Exfiltrates Gigabytes of Data”

“Elon Musk Becomes World’s First Trillionaire Amidst Economic Shifts”

Share This Article
Facebook Twitter Copy Link Print
Previous Article “Huawei Launches HarmonyOS 7 Featuring Sleek Design and Advanced AI” “Huawei Launches HarmonyOS 7 Featuring Sleek Design and Advanced AI”
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Product categories

  • Computer & Accessories
  • Headphones
  • Laptops
  • Phones
  • Wearables

Trending Products

  • SAMSUNG Galaxy A16: Unlocked 128GB Dual SIM in Light Green! SAMSUNG Galaxy A16: Unlocked 128GB Dual SIM in Light Green! $135.00
  • Unlock Creativity: Moto G Stylus 2022 | 50MP Camera & 2-Day Battery Unlock Creativity: Moto G Stylus 2022 | 50MP Camera & 2-Day Battery $179.99
  • BLU G35 2025: Unlocked 6.5” Display & Dual Camera Magic! BLU G35 2025: Unlocked 6.5” Display & Dual Camera Magic! $64.99
  • Avantree HT41899: Dual Bluetooth Headphones for TV Bliss! Avantree HT41899: Dual Bluetooth Headphones for TV Bliss! $171.99 Original price was: $171.99.$119.99Current price is: $119.99.
  • Capture Every Moment: 4K Mini Action Camera Bundle! Capture Every Moment: 4K Mini Action Camera Bundle! $64.99

You Might also Like

“Slate Truck: Can Compact EVs Address America’s Electric Vehicle Challenge?”
Technology

“Slate Truck: Can Compact EVs Address America’s Electric Vehicle Challenge?”

Admin Admin 5 Min Read
“SpaceX Sets Record with 5 Share Price in Historic IPO”
Technology

“SpaceX Sets Record with $135 Share Price in Historic IPO”

Admin Admin 3 Min Read
“Microsoft Resolves 0-Day Vulnerability Amid Rivalry with Researcher”
Technology

“Microsoft Resolves 0-Day Vulnerability Amid Rivalry with Researcher”

Admin Admin 3 Min Read

About Us

At The Tech Diff, we believe technology is more than just innovation—it’s a lifestyle that shapes the way we work, connect, and explore the world. Our mission is to keep readers informed, inspired, and ahead of the curve with fresh updates, expert insights, and meaningful stories from across the digital landscape.

Useful Link

  • Shop
  • About
  • Contact
  • Terms & Conditions
  • Privacy Policy

Categories

  • Computers
  • Phones
  • Technology
  • Wearables

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

We don’t spam! Read our privacy policy for more info.

Check your inbox or spam folder to confirm your subscription.

The Tech DiffThe Tech Diff
Follow US
© Copyright 2022. All Rights Reserved By The Tech Diff.
Welcome Back!

Sign in to your account

Lost your password?