Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads
- Attackers cloned AI skills, later adding malicious code to steal credentials
- Zenity Labs found millions of installs and dozens of dangerous skill variants
- Vercel and Microsoft removed malicious skills, but manual removal is still required
AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.
Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.
However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the AI agents to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers.
Latest Videos FromTechRadar
Dozens of malicious skills
While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users).
And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks.
These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update.
Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
![]()
The best antivirus for all budgets

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Attackers cloned AI skills, later adding malicious code to steal credentials Zenity Labs found millions of installs and dozens of dangerous skill variants Vercel and Microsoft removed malicious skills, but manual removal is still required AI skills, instructions that teach AI agents how to do certain tasks and thus extend…
Recent Posts
- Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads
- Grab the entire Lord of the Rings trilogy on 4K Blu-Ray for $50
- I tested Turtle Beach’s newest controller, and I can’t imagine using anything else for GTA 6 — it’s got an illuminated skyline and tropical vibes; what more could you want?
- Are USB flash drives becoming obsolete?
- Samsung’s Z Fold 8 Ultra is more of the same, but better than ever
Archives
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023