Malicious AI Skills Amass 1.7 Million Installs as Attackers Target AI Agent Supply Chain
Security researchers at Zenity Labs exposed a sophisticated credential-stealing campaign targeting AI agents through skills.sh, Vercel's public registry for AI agent skills. Attackers cloned legitimate AI agent add-ons into typosquatted versions, accumulated over 1.7 million aggregate installs, then activated malicious instructions to exfiltrate SSH keys, cloud credentials, and sensitive data.