AUTO-UPDATED

Malicious AI ‘skills’ turned agents into credential thieves, at scale

Security researchers at Zenity Labs discovered a malicious credential-stealing campaign targeting AI agents through typosquatted add-ons hosted on the Vercel-run skills.sh registry for AI tools.

Key Points

  • Attackers cloned legitimate AI skills and injected malicious instructions designed to exfiltrate SSH keys, cloud credentials, and database logins.
  • One malicious skill family reached over 1.7 million aggregate installs before being identified and removed by Vercel and GitHub.
  • Over 30% of the identified dangerous skills specifically targeted Claude Code and OpenClaw to deploy malware.
  • Some malicious packages implemented self-preservation tactics, such as rewriting system prompts to prevent deletion or replacing legitimate skill-creator tools.
  • Zenity Labs released a free tool called AI Total that sandboxes and analyzes skills to detect hidden malicious behavior before execution.

Why it Matters

This incident highlights a critical vulnerability in the AI agent supply chain where instructions, rather than traditional code, are weaponized to compromise user data. As agents gain broader access to sensitive systems, the ability for malicious actors to hide instructions in seemingly benign tools poses a significant security risk for enterprise and individual users.
The Next Web Published by Ana Maria Constantin
Read original