frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Microsoft's open source tools were hacked to steal passwords of AI developers

https://techcrunch.com/2026/06/08/microsofts-open-source-tools-were-hacked-to-steal-passwords-of-ai-developers/
91•raffael_de•1h ago

Comments

TZubiri•55m ago
another day, another supply chain vulnerability
axus•52m ago
Their source has the list of the 73 disabled repositories: https://opensourcemalware.com/blog/miasma-reaches-azure
antiloper•50m ago
AI;DR:

Azure (49)

azure-functions-agents-runtime azure-functions-connector-extension azure-functions-core-tools azure-functions-docker azure-functions-dotnet-extensions azure-functions-dotnet-worker azure-functions-durable-extension azure-functions-durable-js azure-functions-durable-powershell azure-functions-durable-python azure-functions-extension-bundles azure-functions-golang-worker azure-functions-host azure-functions-java-library azure-functions-java-worker azure-functions-kafka-extension azure-functions-language-worker-protobuf azure-functions-mcp-extension azure-functions-nodejs-e2e-tests azure-functions-nodejs-library azure-functions-nodejs-opentelemetry azure-functions-nodejs-worker azure-functions-openai-extension azure-functions-powershell-library azure-functions-powershell-opentelemetry azure-functions-powershell-worker azure-functions-python-extensions azure-functions-python-library azure-functions-python-worker azure-functions-rabbitmq-extension azure-functions-skills azure-functions-sql-extension azure-functions-templates azure-functions-tooling-feed azure-functions-vs-build-sdk azure-webjobs-sdk azure-webjobs-sdk-extensions azure-websites-security checkaccess-v2-go-sdk Connectors-NET-LSP Connectors-NET-Samples Connectors-NET-SDK Connectors-NodeJS-SDK connectors-python-sdk durabletask functions-action functions-container-action homebrew-functions sonic-gnmi.msft

microsoft (10)

DurableFunctionsMonitor durabletask-dotnet durabletask-go durabletask-java durabletask-js durabletask-mssql durabletask-netherite durabletask-protobuf Microsoft-Performance-Tools-Apple secure-azureai-agent

Azure-Samples (13)

azure-ai-content-understanding-python azure-container-apps-multi-agent-workflow azure-container-apps-sandboxes azure-functions-java-flex-consumption-azd azure-functions-nodejs-opentelemetry-samples azure-search-openai-demo-purviewdatasecurity functions-connectors-python functions-connectors-typescript llm-fine-tuning openai-chat-app-entra-auth-builtin openai-chat-app-entra-auth-local rag-postgres-openai-python tutor

MicrosoftDocs (1)

windows-driver-docs

JdeBP•42m ago
These seem related:

* https://news.ycombinator.com/item?id=48418318 (The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds)

* https://news.ycombinator.com/item?id=48450543 (Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents)

* https://news.ycombinator.com/item?id=48416155

* https://news.ycombinator.com/item?id=48416269 (Miasma Worm Targets AI Coding Agents via GitHub Repos)

jbverschoor•40m ago
Note that also the homebrew-tap was affected: homebrew-functions
dude250711•37m ago
The Age of Agentic Development.
ares623•37m ago
guys. what the fuck. are we even doing.
larodi•28m ago
getting deeper and deeper. the question is what goes one when breaches reach opensource-based stuff running nuclear reactors. i'd be concerned.
nDRDY•18m ago
We are ever-faster approaching the Anti Singularity, the moment when everything "tech" implodes and progress screeches to a halt.
narrator•13m ago
What if this is "The Great Filter?" [Ominous music plays in the background]
christophilus•6m ago
Downloading OpenBSD and going off-grid. How about you?
protoman3000•35m ago
And we trust these people with the root CA cert in our Secure Boot?
HPsquared•34m ago
Windows Update too!
justinclift•2m ago
More like "forced to accept" rather than "trust".

This latest event just continues Microsoft's track record of being a security problem rather than having their shit together. :(

minraws•33m ago
Remember folks Microsoft has Mythos access
qwertox•28m ago
So it's not only incompetence, but also laziness to use Mythos?
_pdp_•30m ago
What follows next is purely speculation and it is based on my own observations and thoughts but based on what I've seen the old RBAC models, while being almost broken before, now it is fully broken, with the fact that now coding assistants and engineers are working on multiple unrelated projects simultaneously - especially working on wild experiments they had no time for previously. The risk of supply chain issue has increased dramatically in the enterprise.

Again, I am not saying it is related but I think it has an impact.

Now in many places it is encouraged by coders and managers to vibe stuff on their own devices. Soon or later it will become a problem, especially for those that have no idea what they are doing.

I am not saying it is related but I feel that it coincides perfectly.

I just cannot believe there is no underlaying thread going through all of these recent supply chain issues, and yes there are some hacking groups that specialise in this, sure, but it is because the bounty is plentiful.

zihotki•24m ago
And the best recommendation security teams can give - keep your SBOM strict, use min release age policy (sounds more like band-aid). That's a scary world to live in.
wolfi1•11m ago
a friend of mine has a very different solution: he codes everything by hand. he says that the time you need to research to include a new package you can actually use to code the piece you need. and he for sure doesn't have the problems of transitive dependencies
dgellow•2m ago
I assume that means he genAIs all his deps? Rather than writing by hand
axegon_•23m ago
I hate to be the "I told you" guy but... I told you and have been for years. And every time I do, a flock of sloppers come to say "but have you tried the claude sloppus, it's so good man, I haven't written any code in X months". Well.. Enjoy.
bilekas•22m ago
The phrasing of the title is loaded and the content phrases it as some kind of fault of open source.

Then, which I find the most amusing, proceeds to blame MicroSlop for the attempted suuply chain attack,

> Microsoft did not immediately provide the specific number of customers affected, when asked by TechCrunch.

Yeah, because that's how open source works. Tech crunch doing hard work no not explain that.

> This is Microsoft’s second known breach over the past few weeks that has allowed hackers to compromise its open source projects, per Ars Technica.

I, like many others love to knock on Microslop when I can, but in this case they did the right thing. The article phrases it like they did everything wrong, they're all at fault and shame on them for limiting the breach.

This is not the first time I've seen an article from Zack Whittaker that just rubbed me the wrong way.

> steal passwords of AI developers

This phrasing has it's own connotations. AI developers versus developers who use AI?

> This is the latest example in recent months of hackers breaching widely popular open source projects with the aim of planting malware on a large number of users who have the code installed on their computers. These hacks are known as “supply chain” attacks as they target code that is often used in a large number of software products, or by a specific kind of user, which may be advantageous to hack as they sometimes have access to cloud systems and large amounts of customers’ data.

Describes literally nothing of what a supply chain attack is, just the result of one and the reasons for their attack surface.

Very very bad reporting in my opinion. Bad breach, and I hate to admit M$ did the safe and right thing, but this 'reporting' leaves a lot to be desired.

raffael_de•13m ago
What's your post mortem, then? As in - what happened and how should it be read?
bilekas•3m ago
Microsoft's open source projects the target of a supply chain attack and they decided to restrict access to understand and limit exposure ? Something a little more 'true' and less targetted?
bob1029•14m ago
I strongly suspect this is a case of classic personal access tokens being used in an unclean way.

If you are going to be handing tokens to AI agents on weird openclaw contraptions, you should try to use the fine grained variants. My GitHub account spans 3 organizations with wildly differing policies. The fact that classic tokens are even still allowed blows my mind a bit. You should be required to manually opt in each organization at a minimum.

raincole•5m ago
> steal passwords of AI developers

What does this even mean?

The malware specifically steals passwords from developers who use AI? From those who develop AI tool? Or it steals API tokens, which serve a similar function as passwords do for humans?

Is this what journalism looks like today? Just slap the two holy letters on the title and you get views?

(Yes, I read the article. No, I still don't think the title makes sense. You can skip this sloppy techchurch article and read the real information here: https://opensourcemalware.com/blog/miasma-reaches-azure)

dgellow•7m ago
TechCrunch is very sloppy and unreliable. I’ve seen them reporting on things I worked on where they just invented facts for SEO purpose and there is no way to get them to correct

The Simplest Learning Machine

https://medium.com/@VictorBanev/the-simplest-learning-machine-pt-2-e735367f546
1•xaedes•1m ago•0 comments

'They were laughing': Israel's use of rape and sexual abuse in prisons

https://www.aljazeera.com/news/2026/6/9/they-were-laughing-israels-use-of-rape-and-sexual-abuse-i...
2•abdusco•1m ago•0 comments

PingWatch uptime monitoring no server needed (alternativeto UptimeKuma)

https://pingwatch.org
1•pipka•3m ago•0 comments

React Compiler Rust Port

https://github.com/facebook/react/pull/36173
1•maelito•4m ago•0 comments

Safe Terraform auto-apply with conftest

https://www.bejarano.io/terraform-autoapply/
1•ricardbejarano•5m ago•0 comments

Data from 66,000+ musician practice sessions

https://old.reddit.com/r/piano/comments/1u0lyhe/data_from_66000_practice_sessions_how_much_does/
1•sebg•7m ago•0 comments

Show HN: SuperTree – interactive decision tree plot for sklearn,xgboost,lightgbm

https://github.com/mljar/supertree
1•pplonski86•12m ago•0 comments

How to Ditch Codecov for Python Projects

https://hynek.me/articles/ditch-codecov-python/
1•lumpa•16m ago•0 comments

Can a Lego Man Survive a Crash Test? – Invidious

https://inv.nadeko.net/watch?v=JTthuDn638U
1•frans•22m ago•0 comments

What if the GRAVITY suddenly switched off?

https://www.youtube.com/watch?v=dNWwIfjJXZY
2•Asheed•23m ago•0 comments

Htmx Is So Cool I Rolled My Own (2024)

https://dbushell.com/2024/04/16/htmx-and-modern-javascript/
2•birdculture•23m ago•0 comments

Real-Time Capital Flow Analysis Using Window Aggregation

https://medium.com/@DolphinDB_Inc/real-time-capital-flow-analysis-using-window-aggregation-57ba10...
2•Polly_Liu•25m ago•0 comments

Building and Backtesting a Dynamic Grid Trading Strategy for Crypto

https://medium.com/@DolphinDB_Inc/beyond-basic-grid-trading-building-and-backtesting-a-dynamic-st...
2•CrazyTomato•27m ago•0 comments

Palantir is turning the NHS into a tool for mass surveillance

https://www.opendemocracy.net/palantir-is-turning-the-nhs-into-a-tool-for-mass-surveillance/
2•robtherobber•28m ago•0 comments

Do you find yourself aimlessly scrolling? You're not alone

https://www.bbc.com/news/articles/czd2mq505dpo
1•01-_-•35m ago•0 comments

Apple updates child safety inspired by Australia's under-16 ban

https://www.abc.net.au/news/2026-06-09/apple-child-safety-features-revamped/106777228
1•01-_-•35m ago•0 comments

An open-source aircraft identification library in Python

https://github.com/xuhao1/pyAircraftIden
1•marklit•37m ago•0 comments

What if Germany had invested in nuclear power? (2024)

https://doi.org/10.1080/14786451.2024.2355642
2•leonidasrup•39m ago•1 comments

Forever Young: how one molecule can lock plants in a youthful state.(2025)

https://omnia.sas.upenn.edu/story/biologist-scott-poethig-plants-never-age
5•bryanrasmussen•41m ago•0 comments

Broken speaker? Anticonsumerist Repair Cafes urge you to fix it instead of pitch

https://apnews.com/article/repair-cafes-economy-anticonsumerism-affordability-buy-nothing-d3acac3...
2•Physkal•45m ago•0 comments

Uncle Sam considers buying a seat on the Titanic

https://www.theregister.com/ai-and-ml/2026/06/09/uncle-sam-considers-buying-a-seat-on-the-titanic...
4•rbanffy•46m ago•0 comments

How Inclusive Is RTO for Neurodivergent Developers?

https://medium.com/@csal_19296/what-returning-to-the-office-taught-me-about-diversity-in-tech-207...
2•plr_cl•49m ago•0 comments

Apple rebuilt its on-device AI stack at WWDC 2026

https://ziraph.com/blog/apple-on-device-ai-wwdc-2026
2•ABS•51m ago•1 comments

Now what?

https://blog.danieljanus.pl/now-what/
1•nathell•52m ago•0 comments

Random Lives

https://random-lives.github.io/random-lives/
1•dukeyukey•56m ago•0 comments

Due to DMA, Siri AI delayed in EU for iOS 27 and iPadOS 27

https://www.apple.com/newsroom/2026/06/due-to-dma-siri-ai-delayed-in-eu-for-ios-27-and-ipados-27/
1•jllyhill•57m ago•0 comments

A 40-Node 1U Cluster Gigabyte R1C7-K0A-AS1 – ServeTheHome

https://www.servethehome.com/a-40-node-1u-cluster-gigabyte-r1c7-k0a-as1/
1•rbanffy•58m ago•1 comments

An open letter to office suite users, just before the Euro-Office announcement

https://blog.documentfoundation.org/blog/2026/06/08/an-open-letter/
5•maxloh•1h ago•0 comments

A dozen USB chargers in the lab: Apple is good, but not quite the best (2012)

https://www.righto.com/2012/10/a-dozen-usb-chargers-in-lab-apple-is.html
1•arm•1h ago•0 comments

Trace-Based Adaptive Cost-Efficient Routing

https://github.com/adrida/tracer
2•nlpnerd•1h ago•1 comments