• Experts warn malicious AI skills are hitting more victims than ev

    From TechnologyDaily@1337:1/100 to All on Fri Aug 7 18:15:23 2026
    Experts warn malicious AI skills are hitting more victims than ever with one family amassing 1.7 million downloads

    Date:
    Fri, 07 Aug 2026 17:05:00 +0000

    Description:
    What if your AI agent suddenly turned rogue and sent all your passwords to a hacker?

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Attackers cloned AI skills, later adding malicious code to steal credentials Zenity Labs found millions
    of installs and dozens of dangerous skill variants Vercel and Microsoft removed malicious skills, but manual removal is still required AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.

    Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious. However, after a little time had
    past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the AI agents to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were
    then told to package the stolen information with host metadata and send it to the attackers. Latest Videos From TechRadar Watch full video here: Dozens of malicious skills While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed
    more than 1.7 million aggregate installs (not unique users).

    And that is just one skill family, in a sea of malicious skills. The researchers also said they found dozens of additional skills exhibiting
    either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found hundreds of reserved and empty package names that were being kept for future attacks. You may like Multiple
    malicious OpenClaw skills found online - including two macOS infostealers Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers Microsoft warns AI chatbots may be sending victims to malicious websites

    These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update.

    Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before wont be safe until they remove them from their systems manually. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/experts-warn-malicious-ai-skills-are-hi tting-more-victims-than-ever-with-one-family-amassing-1-7-million-downloads


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)