💻
Malicious AI skills stole credentials from millions — one family hit 1.7 million downloads
💻 Technology

Malicious AI skills stole credentials from millions — one family hit 1.7 million downloads

Zenity Labs researchers uncovered a credential-stealing campaign in Vercel's skills.sh public registry for AI agent skills. Attackers cloned legitimate skills, built up download counts, then injected malicious code — one family of fake skills amassed 1.7 million downloads. Vercel and Microsoft removed the malicious skills, but users must manually uninstall them to be safe.

Comments

No comments yet