메뉴
HN
Hacker News 50일 전

마이크로소프트 오픈소스 해킹, AI 개발자 비밀번호 탈취

IMP
9/10
핵심 요약

마이크로소프트의 GitHub에 호스팅된 수십 개의 오픈소스 프로젝트가 해킹당해 악성코드가 삽입되는 사고가 발생했습니다. 이로 인해 AI 개발 도구를 사용하는 개발자들의 비밀번호 및 민감한 자격 증명이 유출될 위험이 있습니다. 이번 사건은 최근 몇 주 내 마이크로소프트 오픈소스 프로젝트에서 발생한 두 번째 공급망(Supply Chain) 공격으로, 방대한 리소스를 가진 대형 기술 기업마저 해킹의 표적이 되었음을 시사합니다.

번역된 본문

마이크로소프트는 해커들이 자사의 오픈소스 프로젝트에 명백히 침투하여 비밀번호를 훔치는 악성코드를 코드에 삽입한 방법을 조사하면서, GitHub에 호스팅된 수십 개의 오픈소스 프로젝트에 대한 접근을 차단했습니다. 영향을 받은 프로젝트 중 상당수는 마이크로소프트의 클라우드 서비스인 Azure 및 개발자들이 Claude Code, Gemini의 CLI(명령줄 인터페이스), VS Code와 같은 AI 개발 앱을 사용해 코딩할 때 사용하는 기타 도구와 관련이 있습니다.

해킹을 가장 먼저 발견한 보안 업체인 Cloudsmith와 커뮤니티 주도의 악성코드 분석 사이트인 OpenSourceMalware에 따르면, 이 악성코드는 사용자가 AI 코딩 앱에서 감염된 도구를 열 때 해커들이 사용자의 비밀번호와 기타 민감한 자격 증명을 훔칠 수 있도록 했습니다. 감염된 도구를 다운로드한 사용자가 얼마나 되는지는 아직 정확히 알려지지 않았습니다.

404 Media가 최초로 보도한 바와 같이, 마이크로소프트는 해당 저장소를 비공개 조치한 사실을 확인했습니다. 마이크로소프트 대변인 Ben Hope는 TechCrunch에 "잠재적인 악성 콘텐츠를 조사하면서 일부 저장소를 임시로 삭제했다"고 밝혔습니다. "일부 저장소는 검토 후 복원되었으며, 나머지는 작업이 계속 진행 중인 관계로 오프라인 상태를 유지할 수 있습니다." Hope는 또한 "조사의 일환으로, 영향을 받은 저장소에서 콘텐츠를 다운로드했을 가능성이 있는 소수의 고객에게 통지했습니다. 조사를 계속 진행할 것이며, 고객의 조치가 필요한 추가적인 사항이 발견되면 기존 지원 채널을 통해 직접 연락할 것"이라고 덧붙였습니다. 마이크로소프트는 TechCrunch의 요청에 피해를 입은 고객의 구체적인 수를 즉시 제공하지는 않았습니다.

마이크로소프트가 소유한 코드 호스팅 사이트인 GitHub에서 프로젝트 페이지에 접속하려고 하면 표시되는 메시지에 따르면, 마이크로소프트 소속의 최소 70개 프로젝트가 '비활성화'되었습니다. "GitHub의 서비스 약관 위반으로 인해 이 저장소에 대한 접근이 GitHub 직원에 의해 비활성화되었습니다."

이 사건은 최근 몇 달 동안 널리 사용되는 인기 오픈소스 프로젝트를 해킹하여 코드가 설치된 수많은 사용자의 컴퓨터에 악성코드를 심는 사례 중 최신 사례입니다. 이러한 해킹은 다수의 소프트웨어 제품이나 특정 사용자 계층에서 자주 사용되는 코드를 표적으로 삼기 때문에 '공급망(Supply Chain)' 공격으로 불립니다. 이는 클라우드 시스템과 대량의 고객 데이터에 대한 접근 권한을 가진 사용자들을 해킹하는 데 유리할 수 있기 때문입니다.

오픈소스 프로젝트의 단독 개발자가 해커의 표적이 되는 것은 드문 일이 아닙니다. 어떤 경우에는 개발자의 신뢰를 얻기 위한 장기적인 노력의 일환으로 진행되기도 합니다. 하지만 이러한 종류의 공격을 방어할 리소스를 갖춘 마이크로소프트와 같은 대형 기술 거인이 해킹을 당하는 것은 매우 이례적인 일입니다.

Ars Technica에 따르면, 이번 사건은 지난 몇 주 동안 마이크로소프트의 오픈소스 프로젝트가 해킹당한 것으로 알려진 두 번째 사건입니다. 5월 중순에 보안 연구원들은 개발자가 앱을 구축하는 데 도움을 주는 도구인 마이크로소프트의 오픈소스 프로젝트 'Durable Task'가 해킹당했다고 밝혔습니다. OpenSourceMalware는 마이크로소프트의 이번 최신 사건이 Durable Task 프로젝트의 '재침해'라고 밝혔는데, 이는 마이크로소프트가 첫 번째 시도에서 해커를 완전히 박멸하지 못했거나 완전히 새롭고 별개의 침해가 발생했을 가능성을 시사합니다.

마이크로소프트의 코멘트와 함께 업데이트되었습니다.

주제: Claude, 사이버 보안, 데이터 유출, Gemini, GitHub, 마이크로소프트, 오픈소스, 보안

기사 내 링크를 통해 구매하시면 소정의 수수료를 받을 수 있습니다. 이는 당사의 편집 독립성에 영향을 미치지 않습니다.

Zack Whittaker 보안 에디터 Zack Whittaker는 TechCrunch의 보안 에디터입니다. 또한 매주 발행되는 사이버 보안 뉴스레터인 'this week in security'의 저자이기도 합니다. Signal에서 zackwhittaker.1337으로 암호화된 메시지를 통해 연락하거나 이메일(zack.whittaker@techcrunch.com)로 연락하거나 아웃리치를 확인할 수 있습니다.

6월 18일 로스앤젤레스 Mach Industries, Founders Fund, Shinkei Systems의 리더들로부터 규모 확장과 성공을 위한 내부적인 통찰력을 얻어보세요. 솔직한 대담한 화중담(Fireside Chat)과 높은 영향력을 미치는 네트워킹을 통해 귀중한 인사이트를 얻으실 수 있습니다.

원문 보기
원문 보기 (영어)
Microsoft has cut off access to dozens of its open source projects hosted on GitHub as it investigates how hackers apparently breached the projects and injected password-stealing malware into the code. Many of the affected projects relate to Microsoft's cloud service Azure and other tools used by developers to code with AI development apps, such as Claude Code, Gemini's command line interface, and VS Code. According to security firm Cloudsmith and community-driven malware analysis site OpenSourceMalware , which were some of the first to flag the hack, the malware allowed the hackers to steal the users' passwords and other sensitive credentials when they opened the compromised tools in their AI coding apps. It's not immediately known how many people have downloaded the affected tools. Microsoft confirmed it pulled the repos, as first reported by 404 Media . Microsoft spokesperson Ben Hope told TechCrunch that the company has "temporarily removed some repositories as we investigated potential malicious content." "Some of these repos have been restored after review, while others may remain offline while work continues." "As part of our investigation, we notified a small number of customers who may have pulled down content from the affected repositories. We will continue to investigate, and if anything further is identified that requires customer action, we will reach out directly through our established support channels,” added Hope. Microsoft did not immediately provide the specific number of customers affected, when asked by TechCrunch. At least 70 projects belonging to Microsoft have been "disabled," per a message loading when trying to access the projects' pages on GitHub, a code-hosting site that Microsoft owns. "Access to this repository has been disabled by GitHub Staff due to a violation of GitHub's terms of service." This is the latest example in recent months of hackers breaching widely popular open source projects with the aim of planting malware on a large number of users who have the code installed on their computers. These hacks are known as "supply chain" attacks as they target code that is often used in a large number of software products, or by a specific kind of user, which may be advantageous to hack as they sometimes have access to cloud systems and large amounts of customers' data. While it's not uncommon for sole developers of open source projects to be targeted by hackers — in some cases as part of long-running efforts to gain the trust of the developer — it is rare for large tech giants like Microsoft, which have the resources to defend against these kinds of attacks, to get breached. This is Microsoft's second known breach over the past few weeks that has allowed hackers to compromise its open source projects, per Ars Technica . In mid-May, security researchers said that Microsoft's open source project Durable Task, a tool that helps developers build apps, was hacked. OpenSourceMalware said that Microsoft's latest incident is a "re-compromise" of the Durable Task project, suggesting that Microsoft may not have eradicated the hackers on its first attempt or an entirely new, distinct breach. Updated with comment from Microsoft. Topics Claude , cybersecurity , data breach , gemini , GitHub , Microsoft , open source , Security When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Zack Whittaker Security Editor Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security . He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com . View Bio June 18 Los Angeles Get an inside look at what it takes to scale and succeed from leaders at Mach Industries, Founders Fund, and Shinkei Systems. Through candid fireside chats and high-impact networking, you'll walk away with valuable insights and new connections. REGISTER NOW Most Popular WWDC 2026: Everything announced on Siri AI, iOS 27, Apple Intelligence and more Morgan Little Aisha Malik Is this the dawn of the Tokenpocalypse? Anthony Ha Founders share VC horror stories, and some are naming names Julie Bort Google will pay SpaceX $920M per month for compute Sean O'Kane Mira Murati steps back into the spotlight, carefully Connie Loizos Ahead of its IPO, Anthropic's Daniela Amodei shrugs off doubts about AI's returns Marina Temkin Microsoft launches Scout, an OpenClaw-inspired personal assistant Russell Brandom