Urgent.News

What's breaking now, across thousands of outlets.

AI

Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads

What if your AI agent suddenly turned rogue and sent all your passwords to a hacker?

Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads

Cybersecurity researchers at Zenity Labs have uncovered a troubling trend in the escalating threat landscape: malicious AI skills are now infiltrating more victims than ever before. One particularly egregious case involved attackers cloning legitimate AI skills from a public registry, Vercel's skills.sh, and then adding their own malicious code to steal sensitive credentials.

This credential-stealing campaign, highlighted by Zenity Labs, demonstrated how attackers exploit the accessibility of AI skills to carry out sophisticated supply chain attacks. A single skill family managed to amass over 1.7 million downloads, despite initially appearing benign. Over a dozen other dangerous skill variants were identified, with almost a third of these leveraging Claude Code and OpenClaw to distribute malware.

Researchers also discovered hundreds of reserved and empty package names that could be repurposed for future attacks. While Vercel and Microsoft swiftly removed the malicious skills following responsible disclosure, Zenity Labs emphasized that those who installed them before remain at risk and must manually remove the affected skills from their systems.

This incident underscores the rapid adaptation and creative abuse of emerging technologies by cybercriminals, mirroring traditional software supply chain attacks where trusted packages are compromised and updated with malicious content.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in AI

‘Google’s Top AI Brains Are Leaving to Launch Discovery Loop’

Steven Levy, writing for Wired: Today it’s official: After almost 27 years, Dean is leaving Google, along with Ghemawat and two other top-tier AI scientists, to found a company called Discovery Loop .

  • Google AI researchers Dean, Ghemawat, Vinyals, and Le leaving to form Discovery Loop.
  • Discovery Loop includes Vinyals, a VP of research at DeepMind and Gemini technical lead.
  • Company's exodus could impact Google's AI competitiveness in rapidly evolving landscape.

More from Friday 7 August →