Seventy-three packages were found carrying a self-replicating credential stealer that triggers automatically the moment an AI agent opens them.
The malware does not wait for a developer to run a build step. It fires on contact with an AI agent, a detail that distinguishes this from the standard supply chain attack. This is the second time in a matter of weeks that packages associated with Microsoft have been laced with similar malware, suggesting either a persistent attacker or a detection gap the first round of takedowns did not close.
The AI-agent trigger is the significant part. Autonomous agents (tools that browse repositories, install dependencies, and execute code on behalf of developers) have become routine enough to be worth targeting specifically. A human developer might pause at a suspicious install hook; an agent running in an automated pipeline generally will not. Self-replication means the stealer can spread without requiring another human action after the initial trigger.
Two incidents in a few weeks means someone is mapping what Microsoft's defenses catch and what slips through. The chapter is not closed.
