Agents
For the 2nd time in weeks, Microsoft packages laced with credential stealer
Microsoft's durabletask PyPI package was poisoned in May 2026 with credential-harvesting malware that steals secrets from AWS, Azure, GCP, Kubernetes, and 90+ developer tools . In June, 73 Microsoft r
Microsoft's durabletask PyPI package was poisoned in May 2026 with credential-harvesting malware that steals secrets from AWS, Azure, GCP, Kubernetes, and 90+ developer tools . In June, 73 Microsoft repositories were disabled after a malicious commit was pushed to the Azure/durabletask repository using the same compromised contributor account, demonstrating the recurring threat to Microsoft's package ecosystem . The attack planted configuration files that execute a credential-harvesting payload when developers open the repository in AI coding tools or IDEs .
Source: Ars Technica | 2026-06-08