Malicious AI ‘skills’ turned agents into credential thieves, at scale
Security researchers at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry of add-ons for AI agents run by Vercel. They unveiled the research at the Black Hat conference. Attackers had cloned real skills into typosquatted look-alikes. One tainted family racked up over 1.7 million installs, though Zenity stresses that is aggregate downloads, […] This story continues at The Next Web
This is a summary aggregated from NextWeb. Read the complete article on the original site:
Read full article at NextWeb