Trojanized AI Agent Skills Amass 1.7 Million Installs in Supply Chain Attack Targeting Developer Credentials
Zenity Labs, presenting at Black Hat USA, reported that attackers uploaded trojanized AI agent skills to Vercel's
Trojanized skills on Vercel's skills.sh marketplace, active since July 11, exploited a vetting model that relies on point-in-time code review and install counts, allowing malicious logic added after listings gained legitimacy to go undetected. Attackers deliberately targeted Claude Code and OpenClaw, agents with direct shell and filesystem access, as droppers rather than opportunistically abusing popular tools. Marketplace-level removal by Vercel and GitHub closes distribution but does not eliminate copies already active in developer and CI environments, since skill instructions can persist in downstream aggregators and on already-infected machines. Reporting rests on a single primary source, Zenity Labs' own disclosure, with secondary outlets restating rather than independently corroborating its findings, and the 1.7 million install figure reflects cumulative downloads rather than confirmed compromises, from a vendor whose threat-intelligence product benefits from heightened concern over AI agent supply-chain risk. Registries built on static review rather than runtime behavioral analysis will remain unable to catch this attack class before production exposure.
4 sources
- Trojanized AI skills gain 1.7M installs in agent-targeted attack -
CSO Online - Zenity Labs Uncovers 1.7 Million-Install Malicious Skills Campaign and Dozens of Malicious AI Agent Skills -
Business Wire (Zenity Labs) - Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads -
TechRadar - Malicious AI 'skills' turned agents into credential thieves, at scale -
TheNextWeb