AI/ML

Attackers exploit AI skills registry for credential theft

(Adobe Stock)

Coverage from Tech Radar indicates that attackers are exploiting a public registry for AI agent skills to conduct sophisticated supply chain attacks. These malicious actors are cloning legitimate AI skills, initially appearing harmless, and later injecting malicious code to steal sensitive user credentials.

Researchers at Zenity Labs discovered a campaign on skills.sh, a Vercel-hosted registry for AI skills. Threat actors created typosquatted versions of popular skills. After these cloned skills gained significant download numbers, malicious code was introduced to exfiltrate SSH keys, cloud credentials, Git tokens, and other sensitive data. This data was then packaged with host metadata and sent to the attackers.

One skill family alone amassed over 1.7 million installs. Zenity Labs identified dozens of other malicious skills, with nearly a third using specific tools to drop malware. While Vercel and Microsoft have removed the identified malicious skills, users who previously installed them must manually remove them to ensure their systems are secure.

Source: Tech Radar

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds