Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million…
- Attackers cloned AI skills, later adding malicious code to steal credentials
- Zenity Labs found millions of installs and dozens of dangerous skill variants
- Vercel and Microsoft removed malicious skills, but manual removal is still required
AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.
Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.
However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the AI agentsto, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens,...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE