Bottom line: More than 1.7 million downloads of trojanized AI agent skills on skills.sh installed a credential stealer that specifically harvested credentials on developer workstations and CI systems.
Security researchers at Zenity have uncovered an attack campaign in which trojanized skills for AI agents were distributed via the skills.sh platform to install a credential stealer on developer machines and CI systems. The campaign shows that the software supply chain for agentic AI tools is now being deliberately targeted.
On July 11, attackers uploaded manipulated agent skills to the open skills marketplace platform skills.sh, with names that imitated the well-known AI services Paperclip and Browser Use through typosquatting. By August 2, downloads of the affected skills had totaled more than 1.7 million. Skills are text files containing instructions and code examples that guide LLMs to perform specific tasks or use tools and services; the marketplace platform skills.sh is operated by Vercel and enables automatic discoverability of such skills by AI agents.
In preparation, the attackers had set up two GitHub organizations in July named “getpaperclipai” and “browser-use-headless,” which imitated the legitimate organizations paperclipai and browser-use. They then initially uploaded verbatim copies of the official skills to skills.sh to pass marketplace checks, replacing them with malicious versions on July 11. In parallel, the attackers attempted to distribute trojanized packages named paperclip-ai and browser-use-headless via npm and PyPI; however, both registries detected and removed these packages as malicious within hours. The perpetrators then switched to a direct installation instruction from their own GitHub repositories, for example in the skill “paperclip-board,” which instructed agents to clone the repository instead of using the official installation method via npx.
According to Zenity, the payload’s collection logic was specifically targeted at developer workstations, CI runners, and agent workspaces: SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, deployment platforms, databases, infrastructure-as-code tooling, and project .env files. Because many of the uploaded Paperclip skills reference each other and trigger cascading installations, the exact number of unique victims cannot be precisely determined; however, individual skills each recorded around 300,000 installations and at times reached the trending list on skills.sh.
For CISOs, this case marks an extension of classic supply-chain risks into agentic AI ecosystems: attackers are no longer targeting only package registries like npm or PyPI, but also configuration and instruction files that are automatically executed by LLM agents and therefore undergo less classic code review. Organizations using agentic tools such as Paperclip, Claude Code, OpenAI Codex, or Cursor should verify the origin and integrity of the skills they use, restrict installation sources to official repositories, and rotate credentials in CI environments and on developer workstations if affected skills have been used.
Source: www.csoonline.com · Published August 7, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.