Microsoft Hacked to Deliver Malware to Claude and Gemini Users
Microsoft's GitHub compromised to deliver malware targeting Claude and Gemini users—a watershed moment for AI agent security.

Why it matters
A major supply-chain security breach targeting AI coding agents exposes critical vulnerabilities in the developer ecosystem that powers enterprise AI deployments. This signals systemic risk in how companies are integrating LLMs into production workflows.
The key facts
5 to knowMicrosoft shut down 70+ GitHub repositories after malware injection
Attack targeted Claude and Gemini users specifically
Malware designed to steal credentials from AI coding agent users
Supply-chain attack vector via trusted developer infrastructure
Impacts enterprise AI agent security posture
Go to the source
404 Media404media.co
Publisher excerpt: Microsoft took the highly unusual step of shutting down more than 70 of its own GitHub repositories after hackers pushed malware that would steal credentials from AI coding agent users.