Zenity Labs Exposes 1.7 Million-Install Malicious AI Skills Campaign
Event summary
- Zenity Labs uncovered a credential-stealing campaign via Vercel’s skills.sh with over 1.7 million aggregate installs.
- The attack targeted AI tools Paperclip and Browser Use using typosquatted skills and look-alike repositories.
- Malware stole sensitive data including SSH keys, cloud credentials, and infrastructure-as-code files from developer workstations.
- Zenity developed AI Total, a free threat intelligence service that dynamically executes AI agent skills in a sandboxed environment.
- Vercel and Microsoft/GitHub removed identified malicious skills within 12 hours of notification.
The big picture
This discovery highlights the growing threat landscape for AI agents, where traditional static analysis fails to detect runtime-based attacks. The incident underscores the need for dynamic threat intelligence tools as AI integration expands across developer workflows and enterprise environments. Zenity’s findings point to a broader trend of supply chain risks extending beyond code dependencies to include skills, tools, and internet content that influence agent behavior.
What we're watching
- Supply Chain Vulnerabilities
- How the expansion of AI supply chain risks will impact developer security practices.
- Dynamic Analysis Adoption
- Whether Zenity’s AI Total service can become an industry standard for detecting runtime threats.
- Malware Evolution
- The pace at which attackers adapt to new detection methods like dynamic skill execution analysis.
Related topics
