frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Microsoft's open source tools were hacked to steal passwords of AI developers

https://techcrunch.com/2026/06/08/microsofts-open-source-tools-were-hacked-to-steal-passwords-of-ai-developers/
105•raffael_de•1h ago

Comments

TZubiri•1h ago
another day, another supply chain vulnerability
axus•1h ago
Their source has the list of the 73 disabled repositories: https://opensourcemalware.com/blog/miasma-reaches-azure
antiloper•1h ago
AI;DR:

Azure (49)

azure-functions-agents-runtime azure-functions-connector-extension azure-functions-core-tools azure-functions-docker azure-functions-dotnet-extensions azure-functions-dotnet-worker azure-functions-durable-extension azure-functions-durable-js azure-functions-durable-powershell azure-functions-durable-python azure-functions-extension-bundles azure-functions-golang-worker azure-functions-host azure-functions-java-library azure-functions-java-worker azure-functions-kafka-extension azure-functions-language-worker-protobuf azure-functions-mcp-extension azure-functions-nodejs-e2e-tests azure-functions-nodejs-library azure-functions-nodejs-opentelemetry azure-functions-nodejs-worker azure-functions-openai-extension azure-functions-powershell-library azure-functions-powershell-opentelemetry azure-functions-powershell-worker azure-functions-python-extensions azure-functions-python-library azure-functions-python-worker azure-functions-rabbitmq-extension azure-functions-skills azure-functions-sql-extension azure-functions-templates azure-functions-tooling-feed azure-functions-vs-build-sdk azure-webjobs-sdk azure-webjobs-sdk-extensions azure-websites-security checkaccess-v2-go-sdk Connectors-NET-LSP Connectors-NET-Samples Connectors-NET-SDK Connectors-NodeJS-SDK connectors-python-sdk durabletask functions-action functions-container-action homebrew-functions sonic-gnmi.msft

microsoft (10)

DurableFunctionsMonitor durabletask-dotnet durabletask-go durabletask-java durabletask-js durabletask-mssql durabletask-netherite durabletask-protobuf Microsoft-Performance-Tools-Apple secure-azureai-agent

Azure-Samples (13)

azure-ai-content-understanding-python azure-container-apps-multi-agent-workflow azure-container-apps-sandboxes azure-functions-java-flex-consumption-azd azure-functions-nodejs-opentelemetry-samples azure-search-openai-demo-purviewdatasecurity functions-connectors-python functions-connectors-typescript llm-fine-tuning openai-chat-app-entra-auth-builtin openai-chat-app-entra-auth-local rag-postgres-openai-python tutor

MicrosoftDocs (1)

windows-driver-docs

JdeBP•58m ago
These seem related:

* https://news.ycombinator.com/item?id=48418318 (The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds)

* https://news.ycombinator.com/item?id=48450543 (Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents)

* https://news.ycombinator.com/item?id=48416155

* https://news.ycombinator.com/item?id=48416269 (Miasma Worm Targets AI Coding Agents via GitHub Repos)

jbverschoor•56m ago
Note that also the homebrew-tap was affected: homebrew-functions
dude250711•53m ago
The Age of Agentic Development.
ares623•53m ago
guys. what the fuck. are we even doing.
larodi•44m ago
getting deeper and deeper. the question is what goes one when breaches reach opensource-based stuff running nuclear reactors. i'd be concerned.
nDRDY•34m ago
We are ever-faster approaching the Anti Singularity, the moment when everything "tech" implodes and progress screeches to a halt.
narrator•29m ago
What if this is "The Great Filter?" [Ominous music plays in the background]
christophilus•22m ago
Downloading OpenBSD and going off-grid. How about you?
protoman3000•51m ago
And we trust these people with the root CA cert in our Secure Boot?
HPsquared•50m ago
Windows Update too!
justinclift•18m ago
More like "forced to accept" rather than "trust".

This latest event just continues Microsoft's track record of being a security problem rather than having their shit together. :(

minraws•49m ago
Remember folks Microsoft has Mythos access
_pdp_•46m ago
What follows next is purely speculation and it is based on my own observations and thoughts but based on what I've seen the old RBAC models, while being almost broken before, now it is fully broken, with the fact that now coding assistants and engineers are working on multiple unrelated projects simultaneously - especially working on wild experiments they had no time for previously. The risk of supply chain issue has increased dramatically in the enterprise.

Again, I am not saying it is related but I think it has an impact.

Now in many places it is encouraged by coders and managers to vibe stuff on their own devices. Soon or later it will become a problem, especially for those that have no idea what they are doing.

I am not saying it is related but I feel that it coincides perfectly.

I just cannot believe there is no underlaying thread going through all of these recent supply chain issues, and yes there are some hacking groups that specialise in this, sure, but it is because the bounty is plentiful.

altairprime•7m ago
[delayed]
sourcecodeplz•1m ago
one could also vibe-code vanilla, no dependencies.
zihotki•40m ago
And the best recommendation security teams can give - keep your SBOM strict, use min release age policy (sounds more like band-aid). That's a scary world to live in.
wolfi1•27m ago
a friend of mine has a very different solution: he codes everything by hand. he says that the time you need to research to include a new package you can actually use to code the piece you need. and he for sure doesn't have the problems of transitive dependencies
dgellow•18m ago
I assume that means he genAIs all his deps? Rather than writing by hand
axegon_•39m ago
I hate to be the "I told you" guy but... I told you and have been for years. And every time I do, a flock of sloppers come to say "but have you tried the claude sloppus, it's so good man, I haven't written any code in X months". Well.. Enjoy.
bilekas•38m ago
The phrasing of the title is loaded and the content phrases it as some kind of fault of open source.

Then, which I find the most amusing, proceeds to blame MicroSlop for the attempted suuply chain attack,

> Microsoft did not immediately provide the specific number of customers affected, when asked by TechCrunch.

Yeah, because that's how open source works. Tech crunch doing hard work no not explain that.

> This is Microsoft’s second known breach over the past few weeks that has allowed hackers to compromise its open source projects, per Ars Technica.

I, like many others love to knock on Microslop when I can, but in this case they did the right thing. The article phrases it like they did everything wrong, they're all at fault and shame on them for limiting the breach.

This is not the first time I've seen an article from Zack Whittaker that just rubbed me the wrong way.

> steal passwords of AI developers

This phrasing has it's own connotations. AI developers versus developers who use AI?

> This is the latest example in recent months of hackers breaching widely popular open source projects with the aim of planting malware on a large number of users who have the code installed on their computers. These hacks are known as “supply chain” attacks as they target code that is often used in a large number of software products, or by a specific kind of user, which may be advantageous to hack as they sometimes have access to cloud systems and large amounts of customers’ data.

Describes literally nothing of what a supply chain attack is, just the result of one and the reasons for their attack surface.

Very very bad reporting in my opinion. Bad breach, and I hate to admit M$ did the safe and right thing, but this 'reporting' leaves a lot to be desired.

raffael_de•29m ago
What's your post mortem, then? As in - what happened and how should it be read?
bilekas•19m ago
Microsoft's open source projects the target of a supply chain attack and they decided to restrict access to understand and limit exposure ? Something a little more 'true' and less targetted?
bob1029•30m ago
I strongly suspect this is a case of classic personal access tokens being used in an unclean way.

If you are going to be handing tokens to AI agents on weird openclaw contraptions, you should try to use the fine grained variants. My GitHub account spans 3 organizations with wildly differing policies. The fact that classic tokens are even still allowed blows my mind a bit. You should be required to manually opt in each organization at a minimum.

raincole•21m ago
> steal passwords of AI developers

What does this even mean?

The malware specifically steals passwords from developers who use AI? From those who develop AI tool? Or it steals API tokens, which serve a similar function as passwords do for humans?

Is this what journalism looks like today? Just slap the two holy letters on the title and you get views?

(Yes, I read the article. No, I still don't think the title makes sense. You can skip this techchurch slop and read the real information here: https://opensourcemalware.com/blog/miasma-reaches-azure)

yossufyahia•14m ago
It actually feels like nothing is safe now every day you hear about hacking is it from the ai making development weak or ai is getting strong in hacking
Zolomon•13m ago
It was never safe to begin with, that is why the security community has been screaming for resources since the 80s.
dgellow•23m ago
TechCrunch is very sloppy and unreliable. I’ve seen them reporting on things I worked on where they just invented facts for SEO purpose and there is no way to get them to correct

Microsoft's open source tools were hacked to steal passwords of AI developers

https://techcrunch.com/2026/06/08/microsofts-open-source-tools-were-hacked-to-steal-passwords-of-...
107•raffael_de•1h ago•29 comments

Forever Young: how one molecule can lock plants in a youthful state.(2025)

https://omnia.sas.upenn.edu/story/biologist-scott-poethig-plants-never-age
10•bryanrasmussen•57m ago•0 comments

Apple reveals new AI architecture built around Google Gemini models

https://www.macrumors.com/2026/06/08/apple-reveals-new-ai-architecture/
587•unclefuzzy•14h ago•448 comments

OpenCV 5 Is Here: The Biggest Leap in Years for Computer Vision

https://opencv.org/opencv-5/
138•ternaus•3d ago•28 comments

Porting the ThinkPad X61 to Coreboot

https://blog.aheymans.xyz/post/thinkpad_x61/
67•walterbell•5h ago•22 comments

Siri AI

https://www.apple.com/apple-intelligence/
571•0xedb•15h ago•525 comments

Thi.ng – open-source building blocks for computational design and art

https://thi.ng
31•nmstoker•1d ago•5 comments

xAI is looking more like a datacentre REIT than a frontier lab

https://martinalderson.com/posts/xais-new-rental-business/
555•martinald•18h ago•432 comments

Old'aVista – The most powerful guide to the old Internet

https://oldavista.com/
101•abnercoimbre•17h ago•21 comments

Show HN: Performative-UI – A react component library of design tropes

https://vorpus.github.io/performativeUI/
970•lizhang•19h ago•177 comments

EU-banned pesticides found in rice, tea and spices

https://www.foodwatch.org/en/eu-banned-pesticides-found-in-rice-tea-and-spices
407•john-titor•17h ago•179 comments

MiMo-v2.5-Pro-UltraSpeed: 1T model with 1000 tokens per second

https://mimo.xiaomi.com/blog/mimo-tilert-1000tps
567•gainsurier•17h ago•418 comments

Apple Core AI Framework

https://developer.apple.com/documentation/coreai/
295•hmokiguess•14h ago•75 comments

Looking Forward to Postgres 19: Query Hints

https://www.pgedge.com/blog/looking-forward-to-postgres-19-query-hints
155•jjgreen•3d ago•23 comments

Facebook is paying people overseas promoting Alberta separatism

https://www.cbc.ca/news/canada/facebook-overseas-alberta-separtism-9.7223966
106•vrganj•3h ago•34 comments

Show HN: Gitdot – A better GitHub. Open-source, written in Rust

https://gitdot.io/
251•baepaul•16h ago•222 comments

GoGoGrandparent (YC S16) is hiring Back end Engineers

https://www.ycombinator.com/companies/gogograndparent/jobs/2vbzAw8-backend-engineer
1•davidchl•5h ago

Passing DBs through continuations

https://remy.wang/blog/cps.html
54•remywang•2d ago•6 comments

H2JVM – A Haskell Library for Writing JVM Bytecode

https://discourse.haskell.org/t/h2jvm-a-haskell-library-for-writing-jvm-bytecode/14182
4•rowbin•1d ago•0 comments

Ask HN: What are tools you have made for yourself since the advent of AI?

296•aryamaan•15h ago•486 comments

FrontierCode

https://cognition.ai/blog/frontier-code
187•streamer45•12h ago•33 comments

Ask HN: Why hasn't there been a real competitor to Ticketmaster yet?

166•mdni007•15h ago•140 comments

Why are cells small?

https://burrito.bio/essays/what-limits-a-cells-size
146•mailyk•14h ago•68 comments

Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

https://signal.org/blog/pdfs/2026-06-08-uk-surveillance-is-not-safety.pdf
563•g0xA52A2A•13h ago•207 comments

How much do amd64 microarchitecture levels help in Go?

https://lemire.me/blog/2026/06/06/how-much-do-amd64-microarchitecture-levels-help-in-go/
54•zdw•1d ago•28 comments

I'm building a parallel internet, and it's called The Thinnernet

https://inavoyage.blogspot.com/2026/06/im-building-parallel-internet-and-its.html
81•initramfs•13h ago•81 comments

AI is slowing down

https://www.wheresyoured.at/ai-is-slowing-down/
544•crescit_eundo•17h ago•564 comments

Job: Head of Stonehenge

https://www.english-heritage.org.uk/about/our-people/careers-with-us/job-search/default-job-page/...
156•mooreds•6h ago•122 comments

Apple bets cheaper AI will woo small developers

https://techcrunch.com/2026/06/08/apple-bets-cheaper-ai-will-woo-small-developers/
63•jbernardo95•12h ago•25 comments

Launch HN: Intuned (YC S22) – Build and run reliable browser automations as code

https://intunedhq.com
106•fkilaiwi•19h ago•48 comments