UNVERIFIEDSingle SourceFor the 2nd time in weeks, Microsoft packages laced with credential stealerArs Technica|6/8/2026