Security researchers at Zenity Labs discovered a malicious credential-stealing campaign targeting AI agents through typosquatted add-ons hosted on the Vercel-run skills.sh registry for AI tools.
Key Points
- Attackers cloned legitimate AI skills and injected malicious instructions designed to exfiltrate SSH keys, cloud credentials, and database logins.
- One malicious skill family reached over 1.7 million aggregate installs before being identified and removed by Vercel and GitHub.
- Over 30% of the identified dangerous skills specifically targeted Claude Code and OpenClaw to deploy malware.
- Some malicious packages implemented self-preservation tactics, such as rewriting system prompts to prevent deletion or replacing legitimate skill-creator tools.
- Zenity Labs released a free tool called AI Total that sandboxes and analyzes skills to detect hidden malicious behavior before execution.