Malicious AI Skills Amass 1.7 Million Installs as Attackers Target AI Agent Supply Chain

Reviewed byNidhi Govil

2 Sources

Share

Security researchers at Zenity Labs exposed a sophisticated credential-stealing campaign targeting AI agents through skills.sh, Vercel's public registry for AI agent skills. Attackers cloned legitimate AI agent add-ons into typosquatted versions, accumulated over 1.7 million aggregate installs, then activated malicious instructions to exfiltrate SSH keys, cloud credentials, and sensitive data.

Attackers Exploit AI Agent Trust Through Patient Infiltration

Security researchers at Zenity Labs have exposed a sophisticated credential-stealing campaign that weaponizes malicious AI skills against AI agents. The attack, unveiled at the Black Hat conference, targeted skills.sh, a public registry for AI agent skills operated by Vercel

1

. Attackers cloned legitimate skills into typosquatted look-alikes, then waited patiently as download counts climbed. One tainted skill family alone accumulated over 1.7 million aggregate installs before the malicious payload activated

2

.

Source: TechRadar

Source: TechRadar

The strategy hinged on building trust first. The fake AI agent add-ons sat dormant and clean while install counts grew. Only after establishing credibility did attackers slip in malicious instructions that transformed obedient agents into credential thieves. The agents were directed to hunt down SSH keys, cloud credentials, database logins, Git and package manager tokens, Kubernetes and Docker configurations, and access tokens, then bundle them with host metadata and transmit everything to attacker-controlled servers

2

.

AI Agents Become the Attack Surface

This represents a fundamental shift in AI-driven supply-chain attacks. Unlike traditional software supply-chain attacks that compromise code libraries, this campaign exploits how AI agents process instructions. A skill is simply a set of instructions, and an agent's core function is following those instructions from any content it receives. The same obedience that makes agents useful becomes the vulnerability cybercriminals exploit

1

.

Zenity Labs found that more than 30% of the dangerous skills abused Claude Code and OpenClaw to drop malware onto victim systems

2

. Some skills incorporated self-preservation mechanisms. One instructed the agent to rewrite its own system prompt to automatically reinstall itself if deleted. Another quietly uninstalled Claude's built-in skill-creator and replaced it with a counterfeit version without user notification

1

.

Hundreds of Reserved Packages Signal Future Threats

The researchers discovered dozens of additional skills exhibiting malicious or dangerous behavior beyond the headline-grabbing 1.7 million install family. More concerning, Zenity Labs identified hundreds of reserved and empty package names staged for future attacks

2

. This suggests attackers are preparing infrastructure for sustained campaigns against AI agent ecosystems.

Rapid Response Leaves Cleanup Gaps

Following Zenity's responsible disclosure, Vercel and Microsoft's GitHub removed the offending skills, listings, and repositories within 12 hours

1

. However, copied instructions can persist in downstream repositories and on machines that already installed the compromised skills. Anyone who previously installed these AI agent add-ons must remove them manually, as automated cleanup is not possible

2

.

Redefining Supply Chain Risk for AI Systems

This incident expands what constitutes a supply chain for AI systems. For AI agents, the attack surface now includes skills, tools, MCP servers, and any web page the agent reads—each a potential hiding place for instructions that turn the agent against its user. As Zenity CTO Michael Bargury noted, the most dangerous skills "appear benign" until they execute

1

.

Source: The Next Web

Source: The Next Web

Zenity, which sells agent security solutions, released a free tool called AI Total that detonates skills in a sandbox environment to observe their actual behavior before deployment. The tool addresses a critical gap: traditional security measures struggle to detect AI-specific attack vectors where malicious behavior emerges only during execution. Watch for increased scrutiny of public registries and calls for skill verification standards as organizations realize AI agents require fundamentally different security approaches than traditional software. The speed with which cybercriminals adapted supply chain tactics to exploit AI agents signals this is merely the opening chapter in a longer security challenge.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved