Wait, it's the "attackers" that are "stealing code"
Not microsoft github?
After all, the prompter could possibly go and find and put back on the copyright notice and license that has been stripped off the source code and follow that license (very much unlike what microsoft is doing) and the prompter, not microsoft is doing the "stealing"? (Spoiler: copying is not theft and taking an infringing work and correcting the infringement to make it compliant is legal).
As for exfiltrating secrets, the responsibility lies solely with microsoft for copying those.