Seventy-three packages now deploy a self-replicating credential stealer the moment an AI agent opens them. This second wave of attacks targets the automated nature of Microsoft ecosystem tools. It exposes a critical vulnerability in how autonomous agents handle untrusted code. Developers must implement stricter sandboxing to prevent automated data exfiltration.