For the 2nd time in weeks, Microsoft packages laced with credential stealer
Summary
Dozens of Microsoft-hosted software packages were found carrying a credential-stealing payload that activates automatically when opened by an AI agent. The campaign involved 73 packages and used self-replication behavior to spread the stealer once execution began.
Why it matters
If AI agents can be reliably induced to execute malicious packages, software supply-chain attacks get cheaper, faster, and harder to contain.