Microsoft Shuts Down 73 GitHub Repos After Hackers Target AI Coding Tools
Microsoft disabled 73 GitHub repositories after the hacking group TeamPCP planted credential-stealing malware in configuration files that targeted developers using AI coding agents like Claude Code, Gemini CLI, and Cursor.

Key Takeaways
- Hackers from the group TeamPCP planted credential-stealing malware in 73 Microsoft-owned GitHub repositories targeting AI coding agent users
- Popular AI tools including Claude Code, Gemini CLI, Cursor, and VS Code were affected by the supply chain attack
- Microsoft disabled all compromised repositories in a 105-second sweep on June 5 after discovering the breach
- The attack exploited how AI coding agents automatically process repository files without human-level scrutiny of each dependency
Microsoft has disabled 73 of its own GitHub repositories after a hacking group planted malware designed to steal credentials from developers using artificial intelligence coding assistants. The attack targeted popular tools including Claude Code, Gemini CLI, Cursor, and VS Code, marking one of the most significant supply chain attacks against the rapidly growing AI development ecosystem.
How the Attack Unfolded
The hacking group known as TeamPCP injected malicious configuration files into Microsoft repositories related to Azure Functions, Durable Task frameworks, and AI sample applications. When developers opened these compromised repositories using AI coding agents, which are tools that use large language models to help write and review code, the hidden malware would silently harvest their login credentials and access tokens. Microsoft discovered the breach and disabled all 73 repositories in a rapid 105-second sweep on June 5. Of the affected repositories, 49 were tied to Azure cloud computing services. The attack built on an earlier compromise from May when TeamPCP published three malicious versions of the popular durabletask package, which thousands of developers depend on for building reliable cloud applications.
Why AI Coding Agents Are at Risk
AI coding assistants work by reading and analyzing entire code repositories to help developers write software faster. This means they automatically process configuration files, dependencies, and instructions without the same skepticism a human developer might apply. Attackers exploited this inherent trust by hiding credential-stealing code in files that AI agents would parse and execute during normal operation. The incident highlights a growing concern in the AI security community about supply chain attacks, where hackers compromise trusted software sources rather than targeting individual users directly. Even first-party repositories owned by Microsoft itself proved vulnerable to this sophisticated approach.
Microsoft confirmed the takedown, stating it had temporarily removed repositories while investigating potential malicious content. Security researchers warned that the company had not fully protected users after the earlier May compromise of the durabletask package. With millions of developers now relying on AI-powered coding tools in their daily workflows, the incident serves as a stark reminder that the convenience of AI assistance comes with new and evolving security risks that the industry must urgently address.
Stay Informed
Weekly AI marketing insights
Join 5,000+ marketers. Unsubscribe anytime.
