Vercel AI Skill Registry Compromised by Credential Thieves
Security researchers at Zenity Labs discovered a credential-stealing campaign on Vercel's public AI skill registry, skills.sh, where attackers cloned real skills into look-alikes, accumulating over 1.7 million installs. The malicious skills were designed to steal SSH keys, cloud credentials, and database logins, exploiting the AI agents' obedience to instructions. Vercel has since cleaned up the compromised skills, but the incident highlights the vulnerability of AI-powered systems to supply-chain attacks.
Key points
- Vercel's skills.sh registry was compromised by attackers who cloned real skills into look-alike versions, accumulating over 1.7 million installs.
- The malicious skills were designed to steal SSH keys, cloud credentials, and database logins, exploiting the AI agents' obedience to instructions.
- More than 30% of the compromised skills abused Claude Code and OpenClaw to drop malware.
- Some compromised skills enabled self-preservation, allowing them to reinstall themselves if deleted or quietly uninstalling Claude's built-in skill-creator.
- Vercel has since cleaned up the compromised skills, but the incident highlights the vulnerability of AI-powered systems to supply-chain attacks.
Vercel AI Skill Registry Compromised by Credential Thieves
Security researchers at Zenity Labs have uncovered a credential-stealing campaign on Vercel's public AI skill registry, skills.sh. The compromised skills were designed to steal SSH keys, cloud credentials, and database logins, exploiting the AI agents' obedience to instructions.
The attackers cloned real skills into look-alike versions, accumulating over 1.7 million installs. This is a significant number, but Zenity stresses that it represents aggregate downloads, not unique victims. The trick was patience, as the fake skills sat clean while they built trust and install counts. Only later did the attackers slip in malicious instructions.
The compromised skills abused popular AI tools like Claude Code and OpenClaw to drop malware. Some even enabled self-preservation, allowing them to reinstall themselves if deleted or quietly uninstalling Claude's built-in skill-creator.
Vercel has since cleaned up the compromised skills, but the incident highlights the vulnerability of AI-powered systems to supply-chain attacks. This is a wake-up call for developers and users to be more vigilant when using AI-powered tools and services.
Sources
The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.