AI Skills Registry Hacked, Millions Affected
A public registry for AI agent skills has been compromised, allowing attackers to clone and modify skills to steal credentials from millions of installs. Experts warn of the growing threat of supply chain attacks using AI skills. Vercel and Microsoft have removed malicious skills, but manual removal is still required.
Key points
- Zenity Labs discovered a credential-stealing campaign on skills.sh, a public registry for AI agent skills, where threat actors cloned and modified existing skills.
- The attackers introduced malicious code to the cloned skills, instructing AI agents to steal SSH keys, cloud credentials, and other sensitive information.
- A single skill family amassed over 1.7 million aggregate installs, with dozens of malicious skills detected.
- Vercel and Microsoft have removed the malicious skills, but manual removal is still required for affected users.
- Experts warn of the growing threat of supply chain attacks using AI skills, which can have devastating consequences for individuals and organizations.
A recent discovery by security experts at Zenity Labs has highlighted the growing threat of supply chain attacks using AI skills. The researchers found that a public registry for AI agent skills, skills.sh, had been compromised by threat actors.
The attackers cloned and modified existing skills on the registry, introducing malicious code that instructed AI agents to steal sensitive information. This information included SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files, and service account files.
The malicious skills were designed to package the stolen information with host metadata and send it to the attackers. A single skill family amassed over 1.7 million aggregate installs, with dozens of malicious skills detected.
Vercel, the cloud platform that owns the skills.sh registry, and Microsoft have removed the malicious skills. However, manual removal is still required for affected users. This highlights the importance of vigilance and regular monitoring of AI skills and registries to prevent such attacks.
The discovery by Zenity Labs serves as a reminder of the growing threat of supply chain attacks using AI skills. These attacks can have devastating consequences for individuals and organizations, making it essential to take proactive measures to prevent them.
Sources
The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.