Trojanized AI skills gain 1.7M installs in agent-targeted attack
Summary
Attackers have successfully trojanized AI agent skills, gaining over 1.7 million installs by poisoning sharable instruction and configuration files for agentic tools. The malicious skills were designed to download and install credential stealers, targeting sensitive developer information like SSH keys, cloud credentials, and tokens.
IFF Assessment
This article describes a sophisticated attack campaign targeting the AI software supply chain by poisoning AI agent skills, which poses a significant threat to defenders by potentially compromising sensitive credentials and infrastructure.
Defender Context
This incident highlights a growing trend of attackers targeting the AI supply chain by compromising AI agent skills. Defenders should be vigilant about the origins of AI skills and configurations, implementing strict vetting processes and security controls for AI-powered workflows. Monitoring for unusual network activity or unexpected credential exfiltration related to AI agent interactions is crucial.