Cybersecurity · 143 views
Trojanized AI skills gain 1.7M installs in agent-targeted attack
Researchers have uncovered an extremely effective attack campaign that involved AI agent skills trojanized to deploy a credential stealer.
AI Summary
Researchers at Zenity identified a campaign that trojanized AI agent skills to install a credential‑stealing payload. The malicious skills were uploaded on July 11 to the open skills ecosystem at skills.sh, using names that typo‑squatted popular AI services such as Paperclip and Browser Use. By August 2 the compromised skills had been downloaded more than 1.7 million times, illustrating a growing trend of attacks on the AI software supply chain.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedCoverage Context
More from Cybersecurity
Continue reading recent Cybersecurity coverage
- Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessionsContinue reading
- In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility ExposureContinue reading
- OpenAI is preparing a $500 ChatGPT Pro Max plan with faster CodexContinue reading
- Stopping IT Worker Scams Requires Revamped HR ProcessContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow