• 2 min read
Malicious AI skills reached 1.7 million installs
A Zenity Labs investigation found malicious AI-agent skills with 1.7 million installs, credential theft, and dozens of dangerous variants.

Image: TechRadar
AI agent “skills” are becoming a new software supply-chain risk. Zenity Labs says attackers used the public skills.sh registry to distribute credential-stealing variants, with one malicious skill family reaching more than 1.7 million aggregate installs.
The figure does not represent unique users, and Zenity could not determine exactly how many people were compromised. It does, however, show the scale available to attackers when AI extensions are distributed through a trusted catalog.
How the malicious skills worked
The campaign began with cloned skills and typosquatted names designed to resemble legitimate entries. Initially, the copies performed no malicious activity. After they accumulated downloads, attackers added instructions and code that directed AI agents to collect sensitive data, including:
- SSH keys and cloud credentials
- Git and package-manager tokens
- Kubernetes and Docker configurations
- Database and infrastructure-as-code credentials
- Environment files and service-account files
The stolen material was bundled with host metadata and sent to the attackers. That delayed activation mirrors a familiar package-registry attack: establish trust first, then push a harmful update after the software has gained users.
Zenity also found dozens of other skills showing malicious or dangerous behavior. Around 30% of the identified dangerous skills abused Claude Code and OpenClaw to drop malware on targets. Researchers additionally identified hundreds of reserved or empty package names apparently being held for possible future campaigns.

Recommended reading
AI-generated security patches fixed only 26% of CVEs
The tactic adds another supply-chain risk to AI-agent systems, where a skill is not merely a library but a set of instructions that expands what an agent can do. A compromised skill can therefore influence both the agent’s behavior and the credentials available in its execution environment. That risk complements the malicious prompts that previously disrupted AI hacking agents and the false memories attackers can plant in AI agents.
Removal does not undo an installation
After Zenity’s responsible disclosure, Vercel and Microsoft removed the identified skills. That action limits further distribution, but it does not clean systems where the skills were already installed. Zenity warned that users must remove them manually.
The reporting does not establish how many installations exposed credentials, whether stolen data was used successfully, or how quickly every affected system can be identified. It also does not provide a complete list of the malicious skill names in the supplied report.
The central lesson is concrete: registry removal is containment, not remediation. A skill that quietly turns malicious after gaining downloads can bypass the trust users place in an app-store-style catalog, making installation history and credential rotation as important as checking whether the listing is still online.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechRadar


