
Fake AI Agent Skill Slipped Past Every Scanner
A malicious AI agent skill bypassed security checks and was downloaded by over 26,000 users, exposing the growing risks of AI-driven malware in everyday applications.
7 stories tagged Malware

A malicious AI agent skill bypassed security checks and was downloaded by over 26,000 users, exposing the growing risks of AI-driven malware in everyday applications.

Researchers have demonstrated that AI coding assistants can be tricked into executing malware from GitHub repositories that appear clean. This new attack vector exploits how AI agents automatically process and run code, bypassing human review.

Researchers at Microsoft have identified a new type of malware called Crypto Clipper that spreads through USB drives and uses the Tor network to steal cryptocurrency. This highlights the evolving tactics of cybercriminals targeting digital assets.

Microsoft has discovered 73 malicious packages in its ecosystem that contain a self-replicating credential stealer. The malware activates as soon as the packages are opened by an AI agent. This is the second such incident in recent weeks, highlighting a growing threat targeting AI development pipelines.

Malware developers are adding text about nuclear and bioweapons to their code to trigger AI safety refusals. This tactic allows them to bypass detection mechanisms in AI systems designed to prevent harmful content.

A popular USB-connected speaker can be hacked over the air to infect connected computers. The manufacturer doesn't consider this a security flaw.

A sophisticated malware campaign is infecting open source projects and selectively wiping machines in Iran. Developers are urged to check their networks for signs of infection. This highlights the growing risks in open source ecosystems.