Malicious AI skills on Vercel's skills.sh amass 1.7M installs, steal credentials
This digest was compiled by AI from multiple sources — links to the originals are below.

Attackers cloned AI skills on skills.sh, a public registry for AI agent instructions, later injecting malicious code to steal credentials and gaining over 1.7 million aggregate installs. Zenity Labs researchers uncovered the campaign and found dozens of dangerous skill variants, while Vercel and Microsoft removed the identified malicious skills. Manual removal remains required for users who installed the skills, even as the registry has been cleaned.
The Attack Method
In early July, attackers created GitHub organizations getpaperclipai and browser-use-headless, then uploaded typosquatted skills to skills.sh mimicking popular services Paperclip and Browser Use. The clones initially contained no malicious code, allowing them to accumulate downloads. After a delay, the attackers updated the skills to instruct AI agents to download and execute a credential stealer from GitHub, following a failed attempt using npm and PyPI packages. The stealer collected SSH keys, cloud credentials, Git tokens, Kubernetes configurations, database credentials, and environment files, packaging them with host metadata for exfiltration.
Damage and Scope
Zenity Labs reported that a single skill family amassed over 1.7 million aggregate installs by August 2. Dozens of additional skills exhibited malicious or dangerous behavior, with nearly 30% abusing Claude Code and OpenClaw to drop malware. The researchers also identified hundreds of reserved and empty package names likely set aside for future attacks. Targets included developer workstations, CI runners, and AI agent workspaces.
Takedown and Aftermath
Following responsible disclosure, Vercel and Microsoft removed the identified skills from the registry. However, Zenity warns that users who installed the skills before removal remain at risk and must manually delete them from their systems. The findings, published in a Zenity report and presented at Black Hat USA 2026, illustrate how rapidly cybercriminals are adapting to compromise AI-driven supply chains.
What's Next
Zenity Labs urges users to audit their AI agent installations immediately. It remains unclear whether the attackers plan to exploit the reserved package names in future campaigns.
2 sources
Malicious AI skills on Vercel's skills.sh amass 1.7M installs, steal credentials



