Security researchers at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry of add-ons for AI agents run by Vercel. They unveiled the research at the Black Hat conference. Attackers had cloned real skills into typosquatted look-alikes.

One tainted family racked up over 1.7 million installs, though Zenity stresses that is aggregate downloads, not unique victims.

The trick was patience. The fake skills sat clean while they built trust and install counts. Only later did the attackers slip in malicious instructions. Those told the AI agents to hunt down SSH keys, cloud credentials, database logins and access tokens, bundle them with the machine’s details, and ship them to attacker servers.

The agent becomes the weapon

That is what sets this apart from an ordinary supply-chain attack. A skill is just instructions, and an agent’s whole job is to follow instructions from the content it is handed. So the same obedience that makes agents useful becomes the attack surface.