INTEL_REPORT
Ars Technica — Security · published 6/8/2026, 6:34:23 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
For the 2nd time in weeks, Microsoft packages laced with credential stealer 73 packages run self-replicating stealer as soon as they're opened by an AI agent. Dozens of cryptographically verified open source packages from Microsoft were compromised late last week to add advanced credential-stealing code that was triggered when developers opened them in AI coding agents. In all, multiple researchers said , 73 packages were flagged as malicious when automated systems on GitHu…
https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer
sha256:9b85af39cf2e6e61d5116cc5ff70c04048cc418ea808c0d52ef2435752f75323
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.