WorkThe story, in brief

Microsoft Hacked to Deliver Malware to Claude and Gemini Users

Microsoft's GitHub compromised to deliver malware targeting Claude and Gemini users—a watershed moment for AI agent security.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A major supply-chain security breach targeting AI coding agents exposes critical vulnerabilities in the developer ecosystem that powers enterprise AI deployments. This signals systemic risk in how companies are integrating LLMs into production workflows.

The key facts

5 to know
  1. Microsoft shut down 70+ GitHub repositories after malware injection

  2. Attack targeted Claude and Gemini users specifically

  3. Malware designed to steal credentials from AI coding agent users

  4. Supply-chain attack vector via trusted developer infrastructure

  5. Impacts enterprise AI agent security posture

Go to the source

404 Media404media.co

Publisher excerpt: Microsoft took the highly unusual step of shutting down more than 70 of its own GitHub repositories after hackers pushed malware that would steal credentials from AI coding agent users.
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work