← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 7, 2026 · 17:45via CSO Online

Trojanized AI skills gain 1.7M installs in agent-targeted attack

Brief

Researchers have uncovered an extremely effective attack campaign that involved AI agent skills trojanized to deploy a credential stealer. The incident is part of a growing trend in which attackers are targeting the AI software supply chain by poisoning sharable instruction and configuration files for agentic tools.

Discovered by researchers from security firm Zenity, the attack began on July 11 when the malicious skills were uploaded to open agent skills ecosystem skills. sh with names that typosquatted on popular AI-related services Paperclip and Browser Use. By Aug. 2, the skills had amassed over 1. 7 million combined downloads.

The trojanized skills were crafted to instruct AI agents to download and install a credential stealer payload from GitHub directly, after an earlier attempt to use malicious npm and PyPI packages was thwarted.

Read more on CSO Online