For the 2nd time in weeks, Microsoft packages laced with credential stealer

2026-06-08T20:51:43Z5b2da52d48f3ebbce63517e1fd9839d46ea083472299df7689c5dd8d0eb809d5

What happened

Recent Arstechnica security reports describe a wave of high-impact supply-chain and credential-theft incidents and several critical vulnerabilities. Attackers backdoored dozens of packages (including Red Hat/NPM and Microsoft-distributed packages) and deployed credential-stealing payloads that execute when opened by AI agents. Separately, researchers disclosed a critical “BadHost” vulnerability in Starlette (massive reach), published exploit code for Chromium before fixes, a zero-day defeating default Windows 11 BitLocker protections, large-scale dashboarding of stolen Dashlane vaults, and a ˜

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
5b2da52d48f3ebbce63517e1fd9839d46ea083472299df7689c5dd8d0eb809d5
Enrichment time
2026-06-08T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.