AI Safety 🇷🇺 08.08.2026 16:02

Hackers Weaponized AI Agent Skills — Malicious Packages Downloaded 1.7 Million Times

AnthropicAnthropic
Security researchers at Zenity Labs uncovered a campaign on the skills.sh platform where attackers distributed malicious AI agent skills. These skills stole credentials such as SSH keys, cloud credentials, Git tokens, and more. The malicious skills accumulated 1.7 million downloads, with about 30% using Anthropic Claude Code and OpenClaw to spread malware.
Researchers at Zenity Labs uncovered a campaign on the skills.sh platform, a kind of app store for AI agent skills, aimed at stealing credentials. Initially, attackers cloned existing skills and created typosquatted copies that posed no threat. After these skills gained enough downloads, they injected malicious instructions to steal SSH keys, cloud service credentials, Git tokens, package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure credentials, environment files, and service account credentials. The AI agents then packaged the stolen information with host metadata and sent it to the attackers. Zenity Labs could not determine the exact number of victims but reported that one malware family alone collected 1.7 million downloads. Researchers found 'dozens' of additional skills showing malicious or potentially dangerous behavior. Nearly 30% of them used Anthropic Claude Code and OpenClaw to spread malware. Several hundred reserved and empty package names were also found, likely intended for future attacks. This campaign represents a form of supply chain attack using AI, akin to malicious free libraries in traditional software. After being alerted, platform operators Vercel and Microsoft removed the malicious components, but users who previously downloaded them must manually remove the skills from their systems.
Abbreviations
SSH = Secure Shell — Secure Shell (протокол безопасного удалённого доступа)
Source: 3DNews — original
Our earlier posts on this topic ↓
Fresh news