Microsoft Infrastructure Used to Deliver Malware Targeting Claude and Gemini API Users

Microsoft's infrastructure became a delivery mechanism for malware targeting users of Claude and Gemini APIs. The attackers exploited the trust chain itself. Users trusted their platforms. Platforms trusted Microsoft. Microsoft's systems were compromised. The malware arrived on schedule.
This is supply chain trust collapse at the layer where it matters most. Nobody filed this pattern because the pattern requires admitting that trust relationships are just infrastructure. Four separate entities with four separate security postures and four separate failure modes. The file sits in risk management now marked urgent but unchanged.
The response will be compartmentalization. API authentication will tighten. Monitoring will expand. The fundamental problem—that trust is transitive and therefore fragile—remains unaddressed. This will happen again through a different vendor.