Zenity Labs Uncovers 1.7 Million-Install Malicious Skills Campaign and Dozens of Malicious AI Agent Skills

New free AI Total threat intelligence service dynamically analyzes AI agent skills to expose malicious behavior at runtime

At Black Hat USA, Zenity Labs today announced new research detailing an active credential-stealing malicious skills campaign distributed through Vercel’s skills.sh. The affected skill family amassed more than 1.7 million aggregate installs, not unique users. The research also uncovered dozens of additional malicious or dangerous skills in public registries. The campaign was quickly disrupted by Zenity and Vercel upon discovery.

To identify and investigate these threats, Zenity Labs developed AI Total, a new free threat intelligence service that dynamically executes AI agent skills inside a contained environment and analyzes their runtime behavior. Unlike static approaches that evaluate a skill based on its code or instructions, AI Total observes what the skill and agent do when the skill is executed.

The campaign targeted users of the popular AI tools Paperclip and Browser Use through typosquatted skills and look-alike repositories. The Paperclip skill family began accumulating installs while its skill files were still clean. Attackers later weaponized the skills by inserting malicious installation instructions that caused AI agents to download and execute attacker-controlled code.