Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads
Attackers cloned AI skills, later adding malicious code to steal credentials Zenity Labs found millions of installs and dozens of dangerous skill variants Vercel and Microsoft removed malicious skills, but manual removal is still required AI skills, instructions that teach AI agents how to do certai
<![CDATA[ <article> <ul><li><strong>Attackers cloned AI skills, later adding malicious code to steal credentials</strong></li><li><strong>Zenity Labs found millions of installs and dozens of dangerous skill variants</strong></li><li><strong>Vercel and Microsoft removed malicious skills, but manual removal is still required</strong></li></ul><p>AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.</p><p>Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.</p><p>However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a> to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers. </p><h2 id="dozens-of-malicious-skills">Dozens of malicious skills</h2><p>While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users). </p><p>And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks. </p><p>These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update. </p><p>Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.</p> </article> ]]>
Read the full article on TechRadar
Read Full Article →