ended6월 9일· 1 sources

Compromised Microsoft Packages Weaponize AI Agents to Steal Developer Credentials

Microsoft 패키지 또 뚫렸다… AI 에이전트 노린 '공급망 공격' 비상

Why it matters

This incident highlights a severe escalation in supply-chain attacks, specifically targeting the expanding use of AI coding agents in developer workflows. By compromising cryptographically verified packages and harvesting OIDC tokens, threat actors are successfully bypassing established software integrity frameworks like SLSA. This forces the tech industry to urgently re-evaluate the inherent trust placed in official open-source repositories and automated AI tools.

1
Sources
+0
24h
Growth
5d
Active
MicrosoftGitHubCredential stealerMiasmaAI agentsSupply-chain

Sources

Related Issues