Published August 7, 2026 ยท Added August 9, 2026

Trojanized AI skills gain 1.7M installs in agent-targeted attack

CSO Online reports that typosquatted skills in the open skills.sh ecosystem reached 1.7 million installs while instructing AI agents to download a GitHub-hosted credential stealer, highlighting a new supply-chain risk for shared agent tooling and open-source developer workflows.

CSO Online reports that typosquatted skills in the open skills.sh ecosystem reached 1.7 million installs while instructing AI agents to download a GitHub-hosted credential stealer, highlighting a new supply-chain risk for shared agent tooling and open-source developer workflows.

Read the original story.

Source: Csoonline