ended6월 10일· 1 sources
AI Coding Agents Weaponized in Repeated Microsoft npm Supply Chain Breach
Microsoft npm 연쇄 해킹, AI 코딩 에이전트를 자동 공격 트리거로 악용
Why it matters
This breach redefines supply-chain vulnerabilities by turning AI coding assistants into automatic execution triggers, eliminating the need for developers to actively run malicious code. It also highlights a critical flaw in current trust models, as stolen credentials successfully bypassed SLSA provenance checks. The recurring compromise of a major Microsoft account exposes severe gaps in enterprise credential management and ecosystem security.
1
Sources
+0
24h
—
Growth
103d
Active
npmMicrosoftMiasmaSLSAAI agents