kapynOpen Source

For the 2nd time in weeks, Microsoft packages laced with credential stealer

A malicious supply chain attack has been detected, compromising 73 packages with a credential-stealing malware. These packages, when opened by AI agents, execute code that steals sensitive information, posing a significant risk to developer environments.

Ars Technica·Jun 8, 2026

Opening Kapyn…