<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack-omcgoguv6" -->

---
title: Trojanized AI skills gain 1.7M installs in...
description: Security researchers from Zenity uncovered a supply chain attack targeting AI agent skills on the skills.sh marketplace. Attackers typosquatted on popular AI...
canonical: https://daily.dev/posts/trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack-omcgoguv6
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Trojanized AI skills gain 1.7M installs in agent-targeted attack | daily.dev
og:description: Security researchers from Zenity uncovered a supply chain attack targeting AI agent skills on the skills.sh marketplace. Attackers typosquatted on popular AI...
og:url: https://daily.dev/posts/trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack-omcgoguv6
og:image: https://api.daily.dev/og/posts/oMCGOGuv6.png
og:image:alt: Trojanized AI skills gain 1.7M installs in agent-targeted attack
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Trojanized AI skills gain 1.7M installs in agent-targeted attack

**[CSO Online](https://daily.dev/sources/csoonline)** · 5 min read · 0 upvotes · 1 comments

## Summary

Security researchers from Zenity uncovered a supply chain attack targeting AI agent skills on the skills.sh marketplace. Attackers typosquatted on popular AI services Paperclip and Browser Use, uploading trojanized skills that accumulated 1.7 million installs between July 11 and August 2. The malicious skills exploited progressive discovery — a technique for managing LLM context windows — to hide credential-stealing instructions in a secondary setup file. After malicious npm and PyPI packages were removed within hours, attackers pivoted to serving the payload directly from attacker-controlled GitHub repositories. The credential stealer targeted SSH keys, cloud credentials, Git tokens, Kubernetes/Docker configs, and .env files on developer workstations, CI runners, and agent workspaces. Zenity also launched a free sandbox service called AI Total that detonates skills in a live agent environment to detect malicious behavior.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4206851/trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack.html>

## Questions this post answers

### How did attackers get malicious AI agent skills to reach 1.7 million installs on skills.sh?

Attackers created GitHub organizations impersonating the legitimate Paperclip and Browser Use projects, uploaded verbatim copies of official skills to pass marketplace checks, then updated them on July 11 with instructions telling agents to install a credential stealer directly from a GitHub repo. Combined downloads reached over 1.7 million by August 2, with individual skills hitting around 300,000 installs each.

_Teams adopting AI agent skills can follow supply chain incidents like this one on daily.dev before trusting a marketplace listing._

### Why did the malicious skill instructions in the Zenity-reported attack evade detection for weeks?

The malicious command was hidden in a secondary file called setup-installation.md, which agents were told to open only when installing or starting the tool, while the main skill file described legitimate tasks using progressive discovery, a technique meant to keep unnecessary information out of an LLM's context window. This made the payload invisible to anyone only reviewing the primary skill file.

_Reviewing how progressive discovery can hide payloads helps developers auditing agent skills stay ahead on daily.dev._

### What credentials and files were targeted by the credential stealer distributed through the trojanized Paperclip and Browser Use skills?

The stealer targeted SSH keys, cloud credentials, Git and package-manager tokens, Kubernetes and Docker configuration, deployment platform credentials, database credentials, infrastructure-as-code tooling, and project .env files, according to Zenity researchers, aiming specifically at developer workstations, CI runners, and agent workspaces.

_Developers securing CI pipelines and agent workspaces can track findings like these on daily.dev to harden credential storage._

## Community discussion

Top comments from developers on daily.dev.

**@boycaught** · 1 upvotes

> AI makes criminals more efficient. Who saw that coming? /s

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#ai-agents](https://daily.dev/tags/ai-agents), [#mcp](https://daily.dev/tags/mcp)

[View this post on daily.dev](https://daily.dev/posts/trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack-omcgoguv6)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Trojanized AI skills gain 1.7M installs in agent-targeted attack","url":"https://daily.dev/posts/trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack-omcgoguv6","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack-omcgoguv6"},"datePublished":"2026-08-07T17:46:44.977Z","dateModified":"2026-09-14T06:54:40.027Z","description":"Security researchers from Zenity uncovered a supply chain attack targeting AI agent skills on the skills.sh marketplace. Attackers typosquatted on popular AI...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6869fe408a9af34badbdb88b14bb7211?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6869fe408a9af34badbdb88b14bb7211?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack-omcgoguv6","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"cyber,ai-agents,mcp","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Trojanized AI skills gain 1.7M installs in agent-targeted attack"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack-omcgoguv6","comment":[{"@type":"Comment","text":"AI makes criminals more efficient. Who saw that coming? /s","datePublished":"2026-08-07T21:34:30.807Z","url":"https://daily.dev/posts/oMCGOGuv6#c-dNpOEotKX","author":{"@type":"Person","name":".LAG","url":"https://daily.dev/boycaught","image":"https://avatars.githubusercontent.com/u/90856?v=4"},"interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack-omcgoguv6#faq","mainEntity":[{"@type":"Question","name":"How did attackers get malicious AI agent skills to reach 1.7 million installs on skills.sh?","acceptedAnswer":{"@type":"Answer","text":"Attackers created GitHub organizations impersonating the legitimate Paperclip and Browser Use projects, uploaded verbatim copies of official skills to pass marketplace checks, then updated them on July 11 with instructions telling agents to install a credential stealer directly from a GitHub repo. Combined downloads reached over 1.7 million by August 2, with individual skills hitting around 300,000 installs each. Teams adopting AI agent skills can follow supply chain incidents like this one on daily.dev before trusting a marketplace listing."}},{"@type":"Question","name":"Why did the malicious skill instructions in the Zenity-reported attack evade detection for weeks?","acceptedAnswer":{"@type":"Answer","text":"The malicious command was hidden in a secondary file called setup-installation.md, which agents were told to open only when installing or starting the tool, while the main skill file described legitimate tasks using progressive discovery, a technique meant to keep unnecessary information out of an LLM's context window. This made the payload invisible to anyone only reviewing the primary skill file. Reviewing how progressive discovery can hide payloads helps developers auditing agent skills stay ahead on daily.dev."}},{"@type":"Question","name":"What credentials and files were targeted by the credential stealer distributed through the trojanized Paperclip and Browser Use skills?","acceptedAnswer":{"@type":"Answer","text":"The stealer targeted SSH keys, cloud credentials, Git and package-manager tokens, Kubernetes and Docker configuration, deployment platform credentials, database credentials, infrastructure-as-code tooling, and project .env files, according to Zenity researchers, aiming specifically at developer workstations, CI runners, and agent workspaces. Developers securing CI pipelines and agent workspaces can track findings like these on daily.dev to harden credential storage."}}]}
```

