Trojanized AI agent skills deployed as credential stealers achieve 1.7 million installations
Zenity researchers discovered an attack campaign uploading malicious AI agent skills to the open ecosystem skills.sh beginning July 11, with names typosquatting on Paperclip and Browser Use services, accumulating over 1.7 million combined downloads by August 2. The trojanized skills instructed AI agents to download and install credential stealer payloads from GitHub. The incident reflects a growing trend of attackers poisoning sharable instruction and configuration files targeting the AI software supply chain.
Topics
Sources
- Press Read article
Go deeper
This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.