Cyber & Technology — 2026-08-08

Trojanized AI Agent Skills Amass 1.7 Million Installs in Supply Chain Attack Targeting Developer Credentials

BLUFAI agent skill marketplaces lack runtime behavioral controls, leaving developer and CI credential stores exposed to supply chain attacks that persist well beyond any marketplace-level takedown.

Zenity Labs, presenting at Black Hat USA, reported that attackers uploaded trojanized AI agent skills to Vercel's skills.sh marketplace beginning July 11, using typosquatted names and lookalike GitHub organizations to impersonate the Paperclip and Browser Use platforms 12. The skills initially posted clean code to build trust, then were updated with instructions directing agents to install attacker-controlled payloads that harvest SSH keys, cloud credentials, and other developer and CI secrets 12. By August 2 the affected skill family had reached more than 1.7 million aggregate installs, which Zenity said reflects downloads rather than unique victims 123. Zenity also identified dozens of additional malicious or dangerous skills, more than 30 percent of which abused Claude Code and OpenClaw as malware droppers, and said Vercel and Microsoft's GitHub removed the identified skills and repositories within 12 hours of notification 24.

Analysis
Trojanized skills on Vercel's skills.sh marketplace, active since July 11, exploited a vetting model that relies on point-in-time code review and install counts, allowing malicious logic added after listings gained legitimacy to go undetected. Attackers deliberately targeted Claude Code and OpenClaw, agents with direct shell and filesystem access, as droppers rather than opportunistically abusing popular tools. Marketplace-level removal by Vercel and GitHub closes distribution but does not eliminate copies already active in developer and CI environments, since skill instructions can persist in downstream aggregators and on already-infected machines. Reporting rests on a single primary source, Zenity Labs' own disclosure, with secondary outlets restating rather than independently corroborating its findings, and the 1.7 million install figure reflects cumulative downloads rather than confirmed compromises, from a vendor whose threat-intelligence product benefits from heightened concern over AI agent supply-chain risk. Registries built on static review rather than runtime behavioral analysis will remain unable to catch this attack class before production exposure.
4 sources
  1. Trojanized AI skills gain 1.7M installs in agent-targeted attack - CSO Online
  2. Zenity Labs Uncovers 1.7 Million-Install Malicious Skills Campaign and Dozens of Malicious AI Agent Skills - Business Wire (Zenity Labs)
  3. Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads - TechRadar
  4. Malicious AI 'skills' turned agents into credential thieves, at scale - TheNextWeb

View in full brief →

UNCLASSIFIED // OPEN SOURCE